-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The commit diff shows the vulnerability was patched by adding HTML sanitization (via jQuery.text() method) to the 'name' parameter in getTagButtonHtmlInForm. This function constructs tag display buttons using user-supplied input without proper escaping in vulnerable versions. The CWEs (79/94) and advisory descriptions both indicate unvalidated input in web page generation as the root cause, directly matching this function's pre-patch behavior.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| microweber/microweber | composer | <= 1.3.1 | 1.3.2 |
Ongoing coverage of React2Shell