Vulnerabilities (CVE)

Filtered by vendor Materializecss Subscribe
Filtered by product Materialize
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25349 1 Materializecss 1 Materialize 2024-11-21 4.3 MEDIUM 5.4 MEDIUM
All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.
CVE-2019-11004 1 Materializecss 1 Materialize 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In Materialize through 1.0.0, XSS is possible via the Toast feature.
CVE-2019-11003 1 Materializecss 1 Materialize 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In Materialize through 1.0.0, XSS is possible via the Autocomplete feature.
CVE-2019-11002 1 Materializecss 1 Materialize 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In Materialize through 1.0.0, XSS is possible via the Tooltip feature.