Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-hh8m-fm6v-7cvg
  • npm/@angular/compiler
  • npm/@angular/core
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler 10 Sep
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-jj27-h5hq-8x99
  • npm/@angular/compiler
  • npm/@angular/core
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes 03 Aug
  • Fix available
  • Severity - 7.6 (High)
GHSA-f3m7-gqxr-g87x
  • npm/@angular/compiler
  • npm/@angular/core
Angular: Template and Attribute Namespace Sanitization Bypass (XSS) 15 Jun
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-692r-grfm-v8x7
  • npm/@angular/core
@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS) 15 Jun
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-rgjc-h3x7-9mwg
  • npm/@angular/core
Angular Client Hydration DOM Clobbering & Response-Cache Poisoning 15 Jun
  • Fix available
  • Severity - 8.6 (High)
GHSA-g93w-mfhg-p222
  • npm/@angular/compiler
  • npm/@angular/core
Angular vulnerable to XSS in i18n attribute bindings 13 Mar
  • Fix available
  • Severity - 8.6 (High)
GHSA-prjf-86w9-mfqv
  • npm/@angular/core
Angular i18n vulnerable to Cross-Site Scripting 27 Feb
  • Fix available
  • Severity - 7.0 (High)
GHSA-jrmj-c5cx-3cw6
  • npm/@angular/compiler
  • npm/@angular/core
Angular has XSS Vulnerability via Unsanitized SVG Script Attributes 09 Jan
  • Fix available
  • Severity - 8.5 (High)
GHSA-c75v-2vq8-878f
  • npm/@angular/core
Angular vulnerable to Cross-site Scripting 27 May 2022
  • Fix available
  • Severity - 5.4 (Medium)