-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from unsafe HTML injection via innerHTML in the getTextHeight function. The GitHub commit 8ec824a explicitly fixes this by changing innerHTML to innerText in tooltips.helper.js. This file is part of the content naming mechanism, and the CWE-79 classification confirms this is an XSS vulnerability caused by improper input neutralization during web page generation.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| ibexa/admin-ui | composer | >= 4.6.0, < 4.6.14 | 4.6.14 |
Ongoing coverage of React2Shell