VYPR

npm package

materialize-css

pkg:npm/materialize-css

Vulnerabilities (4)

  • CVE-2022-25349May 1, 2022
    affected <= 1.0.0

    All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited

  • CVE-2019-11004Apr 8, 2019
    affected <= 1.0.0

    In Materialize through 1.0.0, XSS is possible via the Toast feature.

  • CVE-2019-11003Apr 8, 2019
    affected <= 1.0.0

    In Materialize through 1.0.0, XSS is possible via the Autocomplete feature.

  • CVE-2019-11002Apr 8, 2019
    affected <= 1.0.0

    In Materialize through 1.0.0, XSS is possible via the Tooltip feature.