VYPR

npm package

vis-timeline

pkg:npm/vis-timeline

Vulnerabilities (1)

  • CVE-2020-28487Jan 22, 2021
    affected < 7.4.4fixed 7.4.4

    This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.