VYPR

Datatables.net

by Datatables

CVEs (2)

  • CVE-2020-28458HigDec 16, 2020
    risk 0.41cvss 7.3epss 0.04

    All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.

  • CVE-2021-23445LowSep 27, 2021
    risk 0.13cvss 3.1epss 0.02

    This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.