WS-2020-0093
Published:May 19, 2026
Updated:May 20, 2026
lazysizes before 5.2.1-rc1 are vulnerable to Cross-Site Scripting. The video-embed plugin fails to sanitize the following attributes: data-vimeo, data-vimeoparams, data-youtube and data-ytparams. This allows attackers to execute arbitrary JavaScript in a victim's browser if the attacker has control over the vulnerable attributes.
Affected Packages
lazysizes (CDN_JS):
Affected version(s) >=0.4.0 <5.2.1Fix Suggestion:
Update to version 5.2.1lazysizes (NPM):
Affected version(s) >=0.4.0 <5.2.1Fix Suggestion:
Update to version 5.2.1littlenorth.igloo (NUGET):
Affected version(s) >=5.0.0-beta001 <5.0.4-rc.1Fix Suggestion:
Update to version 5.0.4-rc.1our.umbraco.slimsy (NUGET):
Affected version(s) >=2.0.0-beta1 <2.0.0-beta4Fix Suggestion:
Update to version 2.0.0-beta4our.umbraco.slimsy (NUGET):
Affected version(s) =3.0.0-beta3 <3.0.0-beta4Fix Suggestion:
Update to version 3.0.0-beta4woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/sectionBookblockLayout <dev-feature/sectionClassesFix Suggestion:
Update to version dev-feature/sectionClassesbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/babel/traverse-7.23.6 <=dev-dependabot/npm_and_yarn/y18n-4.0.1Fix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/protectedPageErrorMessage <dev-feature/pwaHowToFix Suggestion:
Update to version dev-feature/pwaHowTowoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/clearCacheUnpublishPost <dev-feature/convertShortcodeToBlocsFix Suggestion:
Update to version dev-feature/convertShortcodeToBlocswoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/mobileLayoutFocusCatalogChild <dev-feature/moreTouristInformationsFix Suggestion:
Update to version dev-feature/moreTouristInformationswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/addResponsiveDisplayOptionMapLayout <dev-feature/addResponsiveOptionsFix Suggestion:
Update to version dev-feature/addResponsiveOptionswoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-addContributorinTeaser <dev-addHeroTitlesToPrintVersionFix Suggestion:
Update to version dev-addHeroTitlesToPrintVersionbpocallaghan/titan (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/resources/assets_setup/browserslist-4.16.6 <dev-L5.2Fix Suggestion:
Update to version dev-L5.2simplon/component_mvc (PHP):
Affected version(s) =dev-master <0.0.1Fix Suggestion:
Update to version 0.0.1derhaeuptling/contao-lazy-images (PHP):
Affected version(s) >=3.0.5 <3.0.7Fix Suggestion:
Update to version 3.0.7bpocallaghan/laravel-admin-starter (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/dns-packet-1.3.4 <dev-dependabot/npm_and_yarn/loader-utils-1.4.2Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/loader-utils-1.4.2pi/pi (PHP):
Affected version(s) >=v2.6.0-beta1 <v2.8.0Fix Suggestion:
Update to version v2.8.0bpocallaghan/titan (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/resources/assets_setup/ansi-html-and-webpack-dev-server--removed <dev-utilsFix Suggestion:
Update to version dev-utilsdavyin/dyniva_ui (PHP):
Affected version(s) =3.x-dev <dev-3.x-esbuildFix Suggestion:
Update to version dev-3.x-esbuildpi/pi (PHP):
Affected version(s) >=dev-laminas <v2.5.0-alpha1Fix Suggestion:
Update to version v2.5.0-alpha1dawehner/lazysizes (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/updateEPagePreviewApi <dev-feature/updatePrintCssFix Suggestion:
Update to version dev-feature/updatePrintCssbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/webpack-dev-middleware-5.3.4 <dev-Laravel_5.4Fix Suggestion:
Update to version dev-Laravel_5.4bpocallaghan/titan (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/resources/assets_setup/postcss-and-laravel-mix-8.4.19 <=dev-dependabot/npm_and_yarn/resources/assets_setup/y18n-4.0.1Fix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/LoaderJS <dev-feature/MetaLangUsageFix Suggestion:
Update to version dev-feature/MetaLangUsagewoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/addBlockTitlesToTabs <dev-feature/addCookieIconForCookiesBannerResponsiveFix Suggestion:
Update to version dev-feature/addCookieIconForCookiesBannerResponsivewoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/addpicto <dev-feature/allow-opacity-bg-paramsFix Suggestion:
Update to version dev-feature/allow-opacity-bg-paramswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/preventTplChoiceWithoutThumbnail <dev-feature/profileCustomPostTypeFix Suggestion:
Update to version dev-feature/profileCustomPostTypebpocallaghan/titan (PHP):
Affected version(s) >=1.0.5 <1.0.9Fix Suggestion:
Update to version 1.0.9bpocallaghan/titan (PHP):
Affected version(s) >=1.0.11 <dev-dependabot/npm_and_yarn/resources/assets_setup/eventsource-1.1.1Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/resources/assets_setup/eventsource-1.1.1visol/viresponsiveimages (PHP):
Affected version(s) >=dev-master <0.9.14Fix Suggestion:
Update to version 0.9.14woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/addIframeResizer <dev-feature/addLabelPublicationDateFix Suggestion:
Update to version dev-feature/addLabelPublicationDatewoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-legacy/develop <dev-loadBlocksCloneLatreFix Suggestion:
Update to version dev-loadBlocksCloneLatrewoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/TmapsV2 <dev-feature/TouristicMapV2Fix Suggestion:
Update to version dev-feature/TouristicMapV2woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/countdownBloc <dev-feature/createdPostsDateFix Suggestion:
Update to version dev-feature/createdPostsDatepressgang-wp/pressgang (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/handlebars-4.7.7 <=dev-dependabot/npm_and_yarn/y18n-4.0.1Fix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/roleMediatheque <dev-feature/rollBackPostCreatedBehaviourFix Suggestion:
Update to version dev-feature/rollBackPostCreatedBehaviourderhaeuptling/contao-lazy-images (PHP):
Affected version(s) >=2.0.0 <3.0.4Fix Suggestion:
Update to version 3.0.4woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-develop_legacy <dev-displayParentTagNameFix Suggestion:
Update to version dev-displayParentTagNamednadesign/silverstripe-lazyloaded-image (PHP):
Affected version(s) =0.2.x-dev <0.3.0Fix Suggestion:
Update to version 0.3.0woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-bugfix/detailsFieldSejourPage <dev-bugfix/mirrorPagePreviewFix Suggestion:
Update to version dev-bugfix/mirrorPagePreviewwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/customHomeUrlMobile <dev-feature/default-tm-confFix Suggestion:
Update to version dev-feature/default-tm-confwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/bookblock <dev-feature/bookblock-textsFix Suggestion:
Update to version dev-feature/bookblock-textswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-revert-390-feature/respCustomAcfmargins <dev-show-sharing-links-on-clickFix Suggestion:
Update to version dev-show-sharing-links-on-clickbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/follow-redirects-1.15.4 <v2.x-devFix Suggestion:
Update to version v2.x-devsimplon/component_mvc (PHP):
Affected version(s) =0.0.2Fix Suggestion:
Update to version no_fixbpocallaghan/titan (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/resources/assets_setup/url-parse-1.5.1 <dev-dependabot/npm_and_yarn/resources/assets_setup/url-parse-1.5.7Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/resources/assets_setup/url-parse-1.5.7bpocallaghan/titan (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/resources/assets_setup/dot-prop-4.2.1 <dev-dependabot/npm_and_yarn/resources/assets_setup/tar-4.4.19Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/resources/assets_setup/tar-4.4.19woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/tradBoutonTelecharger <dev-feature/traductionFix Suggestion:
Update to version dev-feature/traductionbpocallaghan/titan (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/resources/assets_setup/nth-check-and-laravel-mix-2.1.1 <dev-dependabot/npm_and_yarn/resources/assets_setup/minimatch-3.1.2Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/resources/assets_setup/minimatch-3.1.2woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/add-sheet-aspect-on-search <dev-feature/addBadgeForNewWoodyTplsFix Suggestion:
Update to version dev-feature/addBadgeForNewWoodyTplswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/YarnDownload <dev-feature/add-alignement-choice-tabs-blockFix Suggestion:
Update to version dev-feature/add-alignement-choice-tabs-blockbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/url-parse-1.5.1 <dev-dependabot/npm_and_yarn/url-parse-1.5.7Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/url-parse-1.5.7bpocallaghan/laravel-admin-starter (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/path-parse-1.0.7 <dev-dependabot/npm_and_yarn/eventsource-1.1.1Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/eventsource-1.1.1madhouse/craft-starter (PHP):
Affected version(s) >=1.0.1 <1.0.3Fix Suggestion:
Update to version 1.0.3woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/translateDocButtonLabel <dev-feature/translateNL_BEFix Suggestion:
Update to version dev-feature/translateNL_BEpressgang-wp/pressgang (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/grunt-1.3.0 <dev-dependabot/npm_and_yarn/mixin-deep-1.3.2Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/mixin-deep-1.3.2woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-addIconInfoRoute <dev-addLinkedInShareFix Suggestion:
Update to version dev-addLinkedInSharewoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/woody_hawwwai_newitem <dev-feature/woodyseo_canonical_urlFix Suggestion:
Update to version dev-feature/woodyseo_canonical_urlwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/addNoPaddingOptionOnTabs <dev-feature/addPinnableContentFix Suggestion:
Update to version dev-feature/addPinnableContentbpocallaghan/titan (PHP):
Affected version(s) =1.0.3 <1.0.4Fix Suggestion:
Update to version 1.0.4woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/addNewFilterTeaserDesc <dev-feature/addNewRuleRobotsTxtFix Suggestion:
Update to version dev-feature/addNewRuleRobotsTxtbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/color-string-1.6.0 <dev-dependabot/npm_and_yarn/follow-redirects-1.14.7Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/follow-redirects-1.14.7hadwao/image-inliner (PHP):
Affected version(s) >=dev-master <=dev-testsFix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/importDrilldown <dev-feature/improveAccessibilityFix Suggestion:
Update to version dev-feature/improveAccessibilitybpocallaghan/laravel-admin-starter (PHP):
Affected version(s) =dev-version_1 <1.0.1Fix Suggestion:
Update to version 1.0.1derhaeuptling/contao-lazy-images (PHP):
Affected version(s) =3.0.8Fix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/improveRGAA <dev-feature/improveResponsiveOrderWordingFix Suggestion:
Update to version dev-feature/improveResponsiveOrderWordingwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/newFuncHelperProcessSection <dev-feature/newSheetUpdateFix Suggestion:
Update to version dev-feature/newSheetUpdatewoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/NewSw <dev-feature/RedirectPermalinkFix Suggestion:
Update to version dev-feature/RedirectPermalinkbpocallaghan/titan (PHP):
Affected version(s) >=1.2.2 <1.2.7Fix Suggestion:
Update to version 1.2.7voidagency/vactory-project (PHP):
Affected version(s) >=dev-master <1.1.0Fix Suggestion:
Update to version 1.1.0woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/analyticsBtnBlock <dev-feature/bloc-titlesFix Suggestion:
Update to version dev-feature/bloc-titleswoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/manualFocusData <dev-feature/mapsKeysFix Suggestion:
Update to version dev-feature/mapsKeystollwerk/tw-base (PHP):
Affected version(s) >=v3.1.0 <dev-typo3-9Fix Suggestion:
Update to version dev-typo3-9woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feat/AddDataLayer <dev-feature/AddonCookiesFix Suggestion:
Update to version dev-feature/AddonCookieswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/orderByTitleASCFilter <dev-feature/pageTeaserBgMoreDataFix Suggestion:
Update to version dev-feature/pageTeaserBgMoreDatatollwerk/tw-base (PHP):
Affected version(s) >=v4.0.0 <v4.7.0Fix Suggestion:
Update to version v4.7.0x-cart-proj/x-cart-proj (PHP):
Affected version(s) =dev-mainFix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-fix/addTabsBloc <dev-fix/auto-focus-menu-orderFix Suggestion:
Update to version dev-fix/auto-focus-menu-orderwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/favOnMEA <dev-feature/feature/primaryBtnVarFix Suggestion:
Update to version dev-feature/feature/primaryBtnVarbpocallaghan/titan (PHP):
Affected version(s) >=1.0.0 <1.0.2Fix Suggestion:
Update to version 1.0.2woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-fix/setLangOnRestApi <dev-fix/teaserTitleFix Suggestion:
Update to version dev-fix/teaserTitlemadhouse/craft-starter (PHP):
Affected version(s) >=1.0.5 <1.0.10Fix Suggestion:
Update to version 1.0.10woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/highlightsCustomContent <dev-feature/humanizeSheetTitleBreadcrumbFix Suggestion:
Update to version dev-feature/humanizeSheetTitleBreadcrumbtollwerk/tw-base (PHP):
Affected version(s) >=dev-develop <v1.0.0Fix Suggestion:
Update to version v1.0.0woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-misc/addBookingTabs <dev-newHawwwaiSheetFix Suggestion:
Update to version dev-newHawwwaiSheetwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/addDescriptionAttachmentPreview <dev-feature/addFilterLazyImgLandswprSlideFix Suggestion:
Update to version dev-feature/addFilterLazyImgLandswprSlidewoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/CheckSeoField <dev-feature/CleanupRewriteRulesFix Suggestion:
Update to version dev-feature/CleanupRewriteRulesmadhouse/craft-starter (PHP):
Affected version(s) =1.0.0 <dev-andrewmenich-patch-1Fix Suggestion:
Update to version dev-andrewmenich-patch-1bpocallaghan/laravel-admin-starter (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/multi-9f37c16f8f <0.0.1Fix Suggestion:
Update to version 0.0.1woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/respCustomAcfmargins <dev-feature/responsiveOptionsFix Suggestion:
Update to version dev-feature/responsiveOptionswoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/tmapsLibrary <dev-feature/topicsEnhancedFix Suggestion:
Update to version dev-feature/topicsEnhancedwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/upgradeSwiperVersion <dev-feature/woody-animationsFix Suggestion:
Update to version dev-feature/woody-animationsdavyin/dyniva_ui (PHP):
Affected version(s) >=0.x-dev <dev-1.x-dev-lzyFix Suggestion:
Update to version dev-1.x-dev-lzybpocallaghan/titan (PHP):
Affected version(s) =1.2.0 <1.2.1Fix Suggestion:
Update to version 1.2.1pressgang-wp/pressgang (PHP):
Affected version(s) =dev-blurUpFixes <dev-masterFix Suggestion:
Update to version dev-masterwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/addStationPicto <dev-feature/addTablePluginTinyMCEFix Suggestion:
Update to version dev-feature/addTablePluginTinyMCEbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/browserslist-4.16.6 <dev-Laravel_5.2Fix Suggestion:
Update to version dev-Laravel_5.2woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-fix/fixTailleIconsTiktok <dev-fix/landing-swipers-buttonFix Suggestion:
Update to version dev-fix/landing-swipers-buttonwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/EskaladProxy <dev-feature/GeoJSONMeaFix Suggestion:
Update to version dev-feature/GeoJSONMeawoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/addWrapButtonsAcf <dev-feature/addon-thumbnailsFix Suggestion:
Update to version dev-feature/addon-thumbnailswoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/flushOnSaveMenusOld <dev-feature/getPagePreviewJsFix Suggestion:
Update to version dev-feature/getPagePreviewJswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/addMenusBloc <dev-feature/addMoreContextToolsFix Suggestion:
Update to version dev-feature/addMoreContextToolswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/disableLazyfirstSlideOnly <dev-feature/displayAnchorIndexInSummaryFix Suggestion:
Update to version dev-feature/displayAnchorIndexInSummarywoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-gulp_migrate <dev-hideDraftPostsInMenuFix Suggestion:
Update to version dev-hideDraftPostsInMenuetdsolutions/lazysizes (PHP):
Affected version(s) >=dev-master <=2.0.7Fix Suggestion:
Update to version no_fixpressgang-wp/pressgang (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/ini-1.3.7 <dev-timber-v2Fix Suggestion:
Update to version dev-timber-v2woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/termCache <dev-feature/theRoadBookFix Suggestion:
Update to version dev-feature/theRoadBookwebgene/webgene-project (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/messagesLumiplan <dev-feature/mixtGalleryFix Suggestion:
Update to version dev-feature/mixtGallerychibko/contao-bootstrap (PHP):
Affected version(s) >=dev-master <=4.4.x-devFix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-bugfix/section_banner <dev-bugfix/sessionExpirationFix Suggestion:
Update to version dev-bugfix/sessionExpirationdavyin/dyniva_ui (PHP):
Affected version(s) =2.x-dev <2.1.x-devFix Suggestion:
Update to version 2.1.x-devwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/StringTranslation <dev-feature/TplPopinFix Suggestion:
Update to version dev-feature/TplPopinwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-bugfix/add-img-on-list_content <dev-bugfix/createdFrom-functionFix Suggestion:
Update to version dev-bugfix/createdFrom-functionbpocallaghan/titan (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/resources/assets_setup/color-string-1.6.0 <dev-dependabot/npm_and_yarn/resources/assets_setup/follow-redirects-1.14.7Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/resources/assets_setup/follow-redirects-1.14.7woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/singleProductTemplate <dev-feature/sitemap-incFix Suggestion:
Update to version dev-feature/sitemap-incpressgang-wp/pressgang (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/websocket-extensions-0.1.4 <v1.x-devFix Suggestion:
Update to version v1.x-devwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-bugfix/sheetPreviewStartYear <dev-bugfix/unpublishFix Suggestion:
Update to version dev-bugfix/unpublishwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feat/CheckBaliseH1 <1.1.0Fix Suggestion:
Update to version 1.1.0dnadesign/silverstripe-lazyloaded-image (PHP):
Affected version(s) =dev-master <0.1.0Fix Suggestion:
Update to version 0.1.0pressgang-wp/pressgang (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/path-parse-1.0.7 <dev-dependabot/npm_and_yarn/bl-1.2.3Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/bl-1.2.3woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-fix/cropRatioSITMEA <dev-fix/cta-and-text-paddingFix Suggestion:
Update to version dev-fix/cta-and-text-paddingbrunocfalcao/laraflash-website (PHP):
Affected version(s) >=dev-master <=v1.1.8Fix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-addWeatherImg <dev-addWiconClassToPageTermsFix Suggestion:
Update to version dev-addWiconClassToPageTermspressgang-wp/pressgang (PHP):
Affected version(s) =dev-structure <dev-testFix Suggestion:
Update to version dev-testwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/enqueueLibraryMomentTz <dev-feature/faq-to-groupsFix Suggestion:
Update to version dev-feature/faq-to-groupswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-master_legacy <dev-mirrorPageBreadcrumbFix Suggestion:
Update to version dev-mirrorPageBreadcrumbderhaeuptling/contao-lazy-images (PHP):
Affected version(s) >=dev-dev <1.0.3Fix Suggestion:
Update to version 1.0.3Related Resources (1)
Do you need more information?
Contact UsCVSS v4
Base Score:
8.3
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
HIGH
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
7.4
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE