Spin.js
by Spin.js
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-3884 | Med | 0.40 | 6.1 | 0.00 | Mar 11, 2026 | Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an arbitrary key-value pair on Object.prototype through a… | ||
| CVE-2021-46168 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2022 | Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c. |
- risk 0.40cvss 6.1epss 0.00
Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an arbitrary key-value pair on Object.prototype through a…
- risk 0.36cvss 5.5epss 0.01
Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c.