Improper escaping when presenting stored form submissions allowed for an attacker to perform a Cross-Site Scripting attack
The vulnerability was initially patched in version 1.0.2, and version 1.1.0 includes this patch. The bug was then accidentally re-introduced during a merge error, and has been re-patched in versions 2.2.5 and 3.1.1.
{ "nvd_published_at": "2023-04-03T18:15:00Z", "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-04-03T21:06:31Z" }