Robuta

https://retout.co.uk/2024/01/01/trusted-types/ Prevent DOM-XSS with Trusted Types - a smarter DevSecOps approach | Tim Retout Jan 1, 2024 - It can be incredibly easy for a frontend developer to accidentally write a client-side cross-site-scripting (DOM-XSS) security issue, and yet these are hard... dom xsstrusted types https://sboxr.com/ Sboxr | Scanner for DOM XSS and Client-side Security dom xssclient sidescannersecurity https://vuxml.freebsd.org/freebsd/f8b7af82-2116-11f0-8ca6-6c3be5272acd.html VuXML: Grafana -- DOM XSS vulnerability dom xssvuxmlgrafanavulnerability https://advisories.gitlab.com/npm/open-webui/CVE-2025-64495/ Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled... CVE-2025-64495 Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE: The functionality that... https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2026-34716/ AVideo: DOM XSS via Unsanitized Display Name in WebSocket Call Notification | GitLab Advisory... CVE-2026-34716 AVideo: DOM XSS via Unsanitized Display Name in WebSocket Call Notification: The AVideo YPTSocket plugin's caller feature renders incoming call... https://advisories.gitlab.com/npm/@pagefind/modular-ui/CVE-2024-45389/ DOM clobbering could escalate to Cross-site Scripting (XSS) | GitLab Advisory Database (GLAD) CVE-2024-45389 DOM clobbering could escalate to Cross-site Scripting (XSS): Pagefind initializes its dynamic JavaScript and WebAssembly files relative to the... cross site scripting https://advisories.gitlab.com/npm/rollup/CVE-2024-47068/ DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS | GitLab Advisory Database... CVE-2024-47068 DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS: We discovered a DOM Clobbering vulnerability in rollup when bundling... https://advisories.gitlab.com/composer/craftcms/commerce/CVE-2026-25482/ Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard... CVE-2026-25482 Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget): A stored DOM XSS vulnerability exists in... https://advisories.gitlab.com/golang/gogs.io/gogs/CVE-2026-26276/ Gogs: DOM-based XSS via milestone selection | GitLab Advisory Database (GLAD) CVE-2026-26276 Gogs: DOM-based XSS via milestone selection: It was confirmed in a test environment that an attacker can store an HTML/JavaScript payload in a... dom based xssgogsvia https://developer.chrome.com/docs/lighthouse/best-practices/trusted-types-xss Mitigate DOM-based XSS with Trusted Types | Lighthouse | Chrome for Developers Learn more about mitigating DOM-based XSS with Trusted Types dom based xsstrusted typesmitigate https://advisories.gitlab.com/npm/locize/GHSA-w937-fg2h-xhq2/ locize Client SDK: Cross-origin DOM XSS & Handler Hijack Through Missing e.origin Validation in... https://advisories.gitlab.com/composer/yeswiki/yeswiki/CVE-2025-24017/ Unauthenticated DOM Based XSS in YesWiki | GitLab Advisory Database (GLAD) CVE-2025-24017 Unauthenticated DOM Based XSS in YesWiki: It is possible for any end-user to craft a DOM based XSS on all of YesWiki's pages which will be... dom based xssyeswikigitlabadvisorydatabase https://advisories.gitlab.com/npm/telejson/GHSA-ccgf-5rwj-j3hv/ TeleJSON: DOM XSS via unsanitised constructor name in `new Function()` | GitLab Advisory Database... GHSA-ccgf-5rwj-j3hv TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`: telejson versions prior to 6.0.0 (released 2022) are vulnerable to... https://advisories.gitlab.com/npm/clevertap-web-sdk/CVE-2026-26861/ CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent... CVE-2026-26861 CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function: CleverTap Web SDK version 1.15.2 and... dom based xssweb sdkclevertapvulnerablevia https://advisories.gitlab.com/npm/astro/CVE-2024-47885/ DOM Clobbering Gadget found in astro's client-side router that leads to XSS | GitLab Advisory... CVE-2024-47885 DOM Clobbering Gadget found in astro's client-side router that leads to XSS: A DOM Clobbering gadget has been discoverd in Astro's client-side... https://advisories.gitlab.com/npm/directus/GHSA-9qrm-48qf-r2rw/ Directus has a DOM-Based cross-site scripting (XSS) via layout_options | GitLab Advisory Database... GHSA-9qrm-48qf-r2rw Directus has a DOM-Based cross-site scripting (XSS) via layout_options: Directus allows an authenticated attacker to save cross site... https://advisories.gitlab.com/npm/petite-vue-i18n/CVE-2025-53892/ vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes | GitLab... CVE-2025-53892 vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes: The escapeParameterHtml: true option in Vue I18n is... https://advisories.gitlab.com/pypi/open-webui/CVE-2025-64495/ Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled... CVE-2025-64495 Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE: The functionality that... https://advisories.gitlab.com/npm/i18nextify/GHSA-6457-mxpq-4fqq/ i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes | GitLab... GHSA-6457-mxpq-4fqq i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes: Versions of i18nextify prior to 4.0.8...