CVE-2025-8082
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
12/12/2025
Last modified:
12/12/2025
Description
Improper neutralization of the title date in the &#39;VDatePicker&#39; component in Vuetify, allows unsanitized HTML to be inserted into the page. This can lead to a Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss attack. The vulnerability occurs because the &#39;title-date-format&#39; property of the &#39;VDatePicker&#39; can accept a user created function and assign its output to the &#39;innerHTML&#39; property of the title element without sanitization.<br />
<br />
This issue affects Vuetify versions greater than or equal to 2.0.0 and less than 3.0.0.<br />
<br />
Note:<br />
Version 2.x of Vuetify is End-of-Life and will not receive any updates to address this issue. For more information see here https://v2.vuetifyjs.com/en/about/eol/ .
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM



