296,746
Total vulnerabilities in the database
Versions of swagger-ui prior to 2.2.1 are vulnerable to Cross-Site Scripting (XSS). The package allows HTML code in the swagger.apiInfo.description value without proper sanitization, which may allow attackers to execute arbitrary JavaScript.
Upgrade to version 2.2.1 or later.
| Software | From | Fixed in |
|---|---|---|
swagger-ui
|
- | 2.2.1 |