from 0, < 1.17.0
MEDIUM5.5CVE-2025-31475tarteaucitron.js allows prototype pollution via custom text injection from 0, < 1.20.1
MEDIUM5.5CVE-2025-31138tarteaucitron.js allows UI manipulation via unrestricted CSS injection from 0, < 1.20.1
MEDIUM4.8CVE-2025-31476tarteaucitron.js allows url scheme injection via unfiltered inputs from 0, < 1.20.1
MEDIUM4.6tarteaucitron.js vulnerable to Cross-site Scripting
from 0, < 1.13.1
MEDIUM4.4tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability
from 0, < 1.29.0
MEDIUM4.3tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
from 0, < 1.33.0
MEDIUM4.2tarteaucitron.js vulnerable to DOM Clobbering via document.currentScript
from 0, < 1.22.0