Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-j5mf-6rh3-rhgg
  • npm/clevertap-web-sdk
CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function 27 Feb
  • Fix available
  • Severity - 8.3 (High)
GHSA-jfrq-hj9f-c8qx
  • npm/clevertap-web-sdk
CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage 27 Feb
  • Fix available
  • Severity - 8.3 (High)
GHSA-x2ph-qqwm-9cc6
  • npm/clevertap-cordova
CleverTap Cordova plugin vulnerable to Cross-site Scripting 15 Jul 2023
  • Fix available
  • Severity - 9.3 (Critical)