VYPR

Select2

by Select2

npm: select2

Source repositories

CVEs (2)

  • CVE-2016-10744MedMar 27, 2019
    risk 0.33cvss 6.1epss 0.02

    In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.

  • CVE-2026-17528Jul 28, 2026
    risk 0.00cvss epss 0.00

    Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a…