CVE-2025-1461
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
28/05/2025
Last modified:
29/05/2025
Description
Improper neutralization of the value of the &#39;eventMoreText&#39; property of the &#39;VCalendar&#39; component in Vuetify allows unsanitized HTML to be inserted into the page. This can lead to a Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss attack. The vulnerability occurs because the default Vuetify translator will return the translation key as the translation, if it can&#39;t find an actual translation.<br />
<br />
This issue affects Vuetify versions greater than or equal to 2.0.0 and less than 3.0.0.<br />
<br />
Note:<br />
Version 2.x of Vuetify is End-of-Life and will not receive any updates to address this issue. For more information see here https://v2.vuetifyjs.com/en/about/eol/ .
Impact
Base Score 3.x
5.60
Severity 3.x
MEDIUM