VYPR
Medium severity5.4OSV Advisory· Published Jan 31, 2023· Updated Jun 17, 2026

CVE-2022-25979

CVE-2022-25979

Description

Versions of the package jsuites before 5.0.1 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization in the Editor() function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
jsuitesnpm
< 5.0.15.0.1

Affected products

3
  • Jsuites/JsuitesOSV2 versions
    v3.1.0, v3.5.0, v3.7.0, …+ 1 more
    • (no CPE)range: v3.1.0, v3.5.0, v3.7.0, …
    • cpe:2.3:a:jsuites:jsuites:*:*:*:*:*:*:*:*range: <5.0.1
  • ghsa-coords
    Range: < 5.0.1

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.