VYPR

nice-select2

by Bluzky

CVEs (1)

  • CVE-2026-17528MedJul 28, 2026
    risk 0.00cvss 6.1epss 0.00

    Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a…