296,746
Total vulnerabilities in the database
Versions of swagger-ui prior to 2.2.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize JSON schemas, allowing attackers to execute arbitrary JavaScript using <script> tags in the method descriptions.
Upgrade to version 2.2.1 or later.
| Software | From | Fixed in |
|---|---|---|
swagger-ui
|
- | 2.2.1 |