CVE-2021-23445

MEDIUM6.1EPSS 0.35%

Cross site scripting in datatables.net

Published: 9/29/2021Modified: 4/28/2026

Description

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (10)