VYPR
Vendor

Materializecss

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2022-25349MedMay 1, 2022
    risk 0.35cvss 5.4epss 0.01

    All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited…

  • CVE-2019-11004MedApr 8, 2019
    risk 0.33cvss 6.1epss 0.01

    In Materialize through 1.0.0, XSS is possible via the Toast feature.

  • CVE-2019-11003MedApr 8, 2019
    risk 0.00cvss 6.1epss 0.01

    In Materialize through 1.0.0, XSS is possible via the Autocomplete feature.

  • CVE-2019-11002MedApr 8, 2019
    risk 0.00cvss 6.1epss 0.01

    In Materialize through 1.0.0, XSS is possible via the Tooltip feature.