WS-2020-0093
Published:May 14, 2026
Updated:May 14, 2026
lazysizes before 5.2.1-rc1 are vulnerable to Cross-Site Scripting. The video-embed plugin fails to sanitize the following attributes: data-vimeo, data-vimeoparams, data-youtube and data-ytparams. This allows attackers to execute arbitrary JavaScript in a victim's browser if the attacker has control over the vulnerable attributes.
Affected Packages
lazysizes (CDN_JS):
Affected version(s) >=0.4.0 <5.2.1Fix Suggestion:
Update to version 5.2.1lazysizes (NPM):
Affected version(s) >=0.4.0 <5.2.1Fix Suggestion:
Update to version 5.2.1our.umbraco.slimsy (NUGET):
Affected version(s) >=2.0.0-beta1 <2.0.0-beta4Fix Suggestion:
Update to version 2.0.0-beta4our.umbraco.slimsy (NUGET):
Affected version(s) =3.0.0-beta3 <3.0.0-beta4Fix Suggestion:
Update to version 3.0.0-beta4littlenorth.igloo (NUGET):
Affected version(s) >=5.0.0-beta001 <5.0.4-rc.1Fix Suggestion:
Update to version 5.0.4-rc.1woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-gulp_migrate <dev-hideDraftPostsInMenuFix Suggestion:
Update to version dev-hideDraftPostsInMenuwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-addIconInfoRoute <dev-addLinkedInShareFix Suggestion:
Update to version dev-addLinkedInSharewoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/roleMediatheque <dev-feature/rollBackPostCreatedBehaviourFix Suggestion:
Update to version dev-feature/rollBackPostCreatedBehaviourbpocallaghan/titan (PHP):
Affected version(s) =1.2.0 <1.2.1Fix Suggestion:
Update to version 1.2.1woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-fix/fixTailleIconsTiktok <dev-fix/landing-swipers-buttonFix Suggestion:
Update to version dev-fix/landing-swipers-buttonwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/manualFocusData <dev-feature/mapsKeysFix Suggestion:
Update to version dev-feature/mapsKeyswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-bugfix/section_banner <dev-bugfix/sessionExpirationFix Suggestion:
Update to version dev-bugfix/sessionExpirationtollwerk/tw-base (PHP):
Affected version(s) >=dev-develop <v1.0.0Fix Suggestion:
Update to version v1.0.0woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-fix/cropRatioSITMEA <dev-fix/cta-and-text-paddingFix Suggestion:
Update to version dev-fix/cta-and-text-paddingwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-master_legacy <dev-mirrorPageBreadcrumbFix Suggestion:
Update to version dev-mirrorPageBreadcrumbwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/addDescriptionAttachmentPreview <dev-feature/addFilterLazyImgLandswprSlideFix Suggestion:
Update to version dev-feature/addFilterLazyImgLandswprSlidewoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/tradBoutonTelecharger <dev-feature/traductionFix Suggestion:
Update to version dev-feature/traductionwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/customHomeUrlMobile <dev-feature/default-tm-confFix Suggestion:
Update to version dev-feature/default-tm-confbpocallaghan/titan (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/resources/assets_setup/postcss-and-laravel-mix-8.4.19 <=dev-dependabot/npm_and_yarn/resources/assets_setup/y18n-4.0.1Fix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/mobileLayoutFocusCatalogChild <dev-feature/moreTouristInformationsFix Suggestion:
Update to version dev-feature/moreTouristInformationsbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/webpack-dev-middleware-5.3.4 <dev-Laravel_5.4Fix Suggestion:
Update to version dev-Laravel_5.4bpocallaghan/laravel-admin-starter (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/babel/traverse-7.23.6 <=dev-dependabot/npm_and_yarn/y18n-4.0.1Fix Suggestion:
Update to version no_fixbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/path-parse-1.0.7 <dev-dependabot/npm_and_yarn/eventsource-1.1.1Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/eventsource-1.1.1woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-develop_legacy <dev-displayParentTagNameFix Suggestion:
Update to version dev-displayParentTagNamebpocallaghan/laravel-admin-starter (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/browserslist-4.16.6 <dev-Laravel_5.2Fix Suggestion:
Update to version dev-Laravel_5.2woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/clearCacheUnpublishPost <dev-feature/convertShortcodeToBlocsFix Suggestion:
Update to version dev-feature/convertShortcodeToBlocswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-revert-390-feature/respCustomAcfmargins <dev-show-sharing-links-on-clickFix Suggestion:
Update to version dev-show-sharing-links-on-clickwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/sectionBookblockLayout <dev-feature/sectionClassesFix Suggestion:
Update to version dev-feature/sectionClasseswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feat/CheckBaliseH1 <1.1.0Fix Suggestion:
Update to version 1.1.0dnadesign/silverstripe-lazyloaded-image (PHP):
Affected version(s) =0.2.x-dev <0.3.0Fix Suggestion:
Update to version 0.3.0bpocallaghan/titan (PHP):
Affected version(s) >=1.0.0 <1.0.2Fix Suggestion:
Update to version 1.0.2simplon/component_mvc (PHP):
Affected version(s) =0.0.2Fix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/addpicto <dev-feature/allow-opacity-bg-paramsFix Suggestion:
Update to version dev-feature/allow-opacity-bg-paramsbrunocfalcao/laraflash-website (PHP):
Affected version(s) >=dev-master <=v1.1.8Fix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/EskaladProxy <dev-feature/GeoJSONMeaFix Suggestion:
Update to version dev-feature/GeoJSONMeahadwao/image-inliner (PHP):
Affected version(s) >=dev-master <=dev-testsFix Suggestion:
Update to version no_fixvisol/viresponsiveimages (PHP):
Affected version(s) >=dev-master <0.9.14Fix Suggestion:
Update to version 0.9.14woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/bookblock <dev-feature/bookblock-textsFix Suggestion:
Update to version dev-feature/bookblock-textsbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/follow-redirects-1.15.4 <v2.x-devFix Suggestion:
Update to version v2.x-devwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/addStationPicto <dev-feature/addTablePluginTinyMCEFix Suggestion:
Update to version dev-feature/addTablePluginTinyMCEbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/url-parse-1.5.1 <dev-dependabot/npm_and_yarn/url-parse-1.5.7Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/url-parse-1.5.7etdsolutions/lazysizes (PHP):
Affected version(s) >=dev-master <=2.0.7Fix Suggestion:
Update to version no_fixpressgang-wp/pressgang (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/websocket-extensions-0.1.4 <v1.x-devFix Suggestion:
Update to version v1.x-devbpocallaghan/titan (PHP):
Affected version(s) >=1.2.2 <1.2.7Fix Suggestion:
Update to version 1.2.7woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/translateDocButtonLabel <dev-feature/translateNL_BEFix Suggestion:
Update to version dev-feature/translateNL_BEpressgang-wp/pressgang (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/path-parse-1.0.7 <dev-dependabot/npm_and_yarn/bl-1.2.3Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/bl-1.2.3tollwerk/tw-base (PHP):
Affected version(s) >=v4.0.0 <v4.7.0Fix Suggestion:
Update to version v4.7.0woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-legacy/develop <dev-loadBlocksCloneLatreFix Suggestion:
Update to version dev-loadBlocksCloneLatrewoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/addNewFilterTeaserDesc <dev-feature/addNewRuleRobotsTxtFix Suggestion:
Update to version dev-feature/addNewRuleRobotsTxtderhaeuptling/contao-lazy-images (PHP):
Affected version(s) >=dev-dev <1.0.3Fix Suggestion:
Update to version 1.0.3bpocallaghan/titan (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/resources/assets_setup/color-string-1.6.0 <dev-dependabot/npm_and_yarn/resources/assets_setup/follow-redirects-1.14.7Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/resources/assets_setup/follow-redirects-1.14.7woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-fix/addTabsBloc <dev-fix/auto-focus-menu-orderFix Suggestion:
Update to version dev-fix/auto-focus-menu-ordermadhouse/craft-starter (PHP):
Affected version(s) >=1.0.5 <1.0.10Fix Suggestion:
Update to version 1.0.10woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/addResponsiveDisplayOptionMapLayout <dev-feature/addResponsiveOptionsFix Suggestion:
Update to version dev-feature/addResponsiveOptionswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/orderByTitleASCFilter <dev-feature/pageTeaserBgMoreDataFix Suggestion:
Update to version dev-feature/pageTeaserBgMoreDatawoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/preventTplChoiceWithoutThumbnail <dev-feature/profileCustomPostTypeFix Suggestion:
Update to version dev-feature/profileCustomPostTypewoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/termCache <dev-feature/theRoadBookFix Suggestion:
Update to version dev-feature/theRoadBookbpocallaghan/titan (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/resources/assets_setup/nth-check-and-laravel-mix-2.1.1 <dev-dependabot/npm_and_yarn/resources/assets_setup/minimatch-3.1.2Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/resources/assets_setup/minimatch-3.1.2woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-bugfix/sheetPreviewStartYear <dev-bugfix/unpublishFix Suggestion:
Update to version dev-bugfix/unpublishbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) =dev-version_1 <1.0.1Fix Suggestion:
Update to version 1.0.1woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/enqueueLibraryMomentTz <dev-feature/faq-to-groupsFix Suggestion:
Update to version dev-feature/faq-to-groupswebgene/webgene-project (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/addIframeResizer <dev-feature/addLabelPublicationDateFix Suggestion:
Update to version dev-feature/addLabelPublicationDatederhaeuptling/contao-lazy-images (PHP):
Affected version(s) =3.0.8Fix Suggestion:
Update to version no_fixbpocallaghan/titan (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/resources/assets_setup/dot-prop-4.2.1 <dev-dependabot/npm_and_yarn/resources/assets_setup/tar-4.4.19Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/resources/assets_setup/tar-4.4.19woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/StringTranslation <dev-feature/TplPopinFix Suggestion:
Update to version dev-feature/TplPopinbpocallaghan/titan (PHP):
Affected version(s) >=1.0.11 <dev-dependabot/npm_and_yarn/resources/assets_setup/eventsource-1.1.1Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/resources/assets_setup/eventsource-1.1.1madhouse/craft-starter (PHP):
Affected version(s) >=1.0.1 <1.0.3Fix Suggestion:
Update to version 1.0.3woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/highlightsCustomContent <dev-feature/humanizeSheetTitleBreadcrumbFix Suggestion:
Update to version dev-feature/humanizeSheetTitleBreadcrumbwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/improveRGAA <dev-feature/improveResponsiveOrderWordingFix Suggestion:
Update to version dev-feature/improveResponsiveOrderWordingwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-bugfix/detailsFieldSejourPage <dev-bugfix/mirrorPagePreviewFix Suggestion:
Update to version dev-bugfix/mirrorPagePreviewwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/protectedPageErrorMessage <dev-feature/pwaHowToFix Suggestion:
Update to version dev-feature/pwaHowTodnadesign/silverstripe-lazyloaded-image (PHP):
Affected version(s) =dev-master <0.1.0Fix Suggestion:
Update to version 0.1.0woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feat/AddDataLayer <dev-feature/AddonCookiesFix Suggestion:
Update to version dev-feature/AddonCookiespressgang-wp/pressgang (PHP):
Affected version(s) =dev-structure <dev-testFix Suggestion:
Update to version dev-testbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/multi-9f37c16f8f <0.0.1Fix Suggestion:
Update to version 0.0.1voidagency/vactory-project (PHP):
Affected version(s) >=dev-master <1.1.0Fix Suggestion:
Update to version 1.1.0woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/addNoPaddingOptionOnTabs <dev-feature/addPinnableContentFix Suggestion:
Update to version dev-feature/addPinnableContentbpocallaghan/titan (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/resources/assets_setup/browserslist-4.16.6 <dev-L5.2Fix Suggestion:
Update to version dev-L5.2woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/analyticsBtnBlock <dev-feature/bloc-titlesFix Suggestion:
Update to version dev-feature/bloc-titleswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/countdownBloc <dev-feature/createdPostsDateFix Suggestion:
Update to version dev-feature/createdPostsDatebpocallaghan/titan (PHP):
Affected version(s) =1.0.3 <1.0.4Fix Suggestion:
Update to version 1.0.4woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/addWrapButtonsAcf <dev-feature/addon-thumbnailsFix Suggestion:
Update to version dev-feature/addon-thumbnailspressgang-wp/pressgang (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/ini-1.3.7 <dev-timber-v2Fix Suggestion:
Update to version dev-timber-v2woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/disableLazyfirstSlideOnly <dev-feature/displayAnchorIndexInSummaryFix Suggestion:
Update to version dev-feature/displayAnchorIndexInSummarydavyin/dyniva_ui (PHP):
Affected version(s) =3.x-dev <dev-3.x-esbuildFix Suggestion:
Update to version dev-3.x-esbuildwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-addContributorinTeaser <dev-addHeroTitlesToPrintVersionFix Suggestion:
Update to version dev-addHeroTitlesToPrintVersiondawehner/lazysizes (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixpi/pi (PHP):
Affected version(s) >=v2.6.0-beta1 <v2.8.0Fix Suggestion:
Update to version v2.8.0woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/importDrilldown <dev-feature/improveAccessibilityFix Suggestion:
Update to version dev-feature/improveAccessibilitywoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/woody_hawwwai_newitem <dev-feature/woodyseo_canonical_urlFix Suggestion:
Update to version dev-feature/woodyseo_canonical_urlwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/tmapsLibrary <dev-feature/topicsEnhancedFix Suggestion:
Update to version dev-feature/topicsEnhancedwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/upgradeSwiperVersion <dev-feature/woody-animationsFix Suggestion:
Update to version dev-feature/woody-animationswoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-fix/setLangOnRestApi <dev-fix/teaserTitleFix Suggestion:
Update to version dev-fix/teaserTitlewoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/LoaderJS <dev-feature/MetaLangUsageFix Suggestion:
Update to version dev-feature/MetaLangUsagewoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/addBlockTitlesToTabs <dev-feature/addCookieIconForCookiesBannerResponsiveFix Suggestion:
Update to version dev-feature/addCookieIconForCookiesBannerResponsivebpocallaghan/titan (PHP):
Affected version(s) >=1.0.5 <1.0.9Fix Suggestion:
Update to version 1.0.9chibko/contao-bootstrap (PHP):
Affected version(s) >=dev-master <=4.4.x-devFix Suggestion:
Update to version no_fixbpocallaghan/titan (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/resources/assets_setup/ansi-html-and-webpack-dev-server--removed <dev-utilsFix Suggestion:
Update to version dev-utilswoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-bugfix/add-img-on-list_content <dev-bugfix/createdFrom-functionFix Suggestion:
Update to version dev-bugfix/createdFrom-functionwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/addMenusBloc <dev-feature/addMoreContextToolsFix Suggestion:
Update to version dev-feature/addMoreContextToolsbpocallaghan/laravel-admin-starter (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/color-string-1.6.0 <dev-dependabot/npm_and_yarn/follow-redirects-1.14.7Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/follow-redirects-1.14.7woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/CheckSeoField <dev-feature/CleanupRewriteRulesFix Suggestion:
Update to version dev-feature/CleanupRewriteRulesdavyin/dyniva_ui (PHP):
Affected version(s) =2.x-dev <2.1.x-devFix Suggestion:
Update to version 2.1.x-devwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/newFuncHelperProcessSection <dev-feature/newSheetUpdateFix Suggestion:
Update to version dev-feature/newSheetUpdatebpocallaghan/titan (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/resources/assets_setup/url-parse-1.5.1 <dev-dependabot/npm_and_yarn/resources/assets_setup/url-parse-1.5.7Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/resources/assets_setup/url-parse-1.5.7derhaeuptling/contao-lazy-images (PHP):
Affected version(s) >=2.0.0 <3.0.4Fix Suggestion:
Update to version 3.0.4woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/flushOnSaveMenusOld <dev-feature/getPagePreviewJsFix Suggestion:
Update to version dev-feature/getPagePreviewJspi/pi (PHP):
Affected version(s) >=dev-laminas <v2.5.0-alpha1Fix Suggestion:
Update to version v2.5.0-alpha1madhouse/craft-starter (PHP):
Affected version(s) =1.0.0 <dev-andrewmenich-patch-1Fix Suggestion:
Update to version dev-andrewmenich-patch-1woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/YarnDownload <dev-feature/add-alignement-choice-tabs-blockFix Suggestion:
Update to version dev-feature/add-alignement-choice-tabs-blocktollwerk/tw-base (PHP):
Affected version(s) >=v3.1.0 <dev-typo3-9Fix Suggestion:
Update to version dev-typo3-9pressgang-wp/pressgang (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/handlebars-4.7.7 <=dev-dependabot/npm_and_yarn/y18n-4.0.1Fix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/messagesLumiplan <dev-feature/mixtGalleryFix Suggestion:
Update to version dev-feature/mixtGallerybpocallaghan/laravel-admin-starter (PHP):
Affected version(s) >=dev-dependabot/npm_and_yarn/dns-packet-1.3.4 <dev-dependabot/npm_and_yarn/loader-utils-1.4.2Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/loader-utils-1.4.2woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/singleProductTemplate <dev-feature/sitemap-incFix Suggestion:
Update to version dev-feature/sitemap-incx-cart-proj/x-cart-proj (PHP):
Affected version(s) =dev-mainFix Suggestion:
Update to version no_fixwoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/add-sheet-aspect-on-search <dev-feature/addBadgeForNewWoodyTplsFix Suggestion:
Update to version dev-feature/addBadgeForNewWoodyTplswoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/respCustomAcfmargins <dev-feature/responsiveOptionsFix Suggestion:
Update to version dev-feature/responsiveOptionsdavyin/dyniva_ui (PHP):
Affected version(s) >=0.x-dev <dev-1.x-dev-lzyFix Suggestion:
Update to version dev-1.x-dev-lzywoody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-feature/updateEPagePreviewApi <dev-feature/updatePrintCssFix Suggestion:
Update to version dev-feature/updatePrintCssderhaeuptling/contao-lazy-images (PHP):
Affected version(s) >=3.0.5 <3.0.7Fix Suggestion:
Update to version 3.0.7woody-wordpress/woody-theme (PHP):
Affected version(s) >=dev-misc/addBookingTabs <dev-newHawwwaiSheetFix Suggestion:
Update to version dev-newHawwwaiSheetpressgang-wp/pressgang (PHP):
Affected version(s) =dev-dependabot/npm_and_yarn/grunt-1.3.0 <dev-dependabot/npm_and_yarn/mixin-deep-1.3.2Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/mixin-deep-1.3.2woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/favOnMEA <dev-feature/feature/primaryBtnVarFix Suggestion:
Update to version dev-feature/feature/primaryBtnVarwoody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/TmapsV2 <dev-feature/TouristicMapV2Fix Suggestion:
Update to version dev-feature/TouristicMapV2woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-addWeatherImg <dev-addWiconClassToPageTermsFix Suggestion:
Update to version dev-addWiconClassToPageTermspressgang-wp/pressgang (PHP):
Affected version(s) =dev-blurUpFixes <dev-masterFix Suggestion:
Update to version dev-mastersimplon/component_mvc (PHP):
Affected version(s) =dev-master <0.0.1Fix Suggestion:
Update to version 0.0.1woody-wordpress/woody-theme (PHP):
Affected version(s) =dev-feature/NewSw <dev-feature/RedirectPermalinkFix Suggestion:
Update to version dev-feature/RedirectPermalinkRelated Resources (1)
Do you need more information?
Contact UsCVSS v4
Base Score:
8.3
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
HIGH
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
7.4
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE