CVE-2022-25854

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
29/04/2022
Last modified:
23/09/2022

Description

This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the XSS payload.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tagify_project:tagify:*:*:*:*:*:*:*:* 4.9.8 (excluding)