In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
{ "binaries": [ { "binary_name": "libjs-dojo-core", "binary_version": "1.10.4+dfsg-2ubuntu0.1~esm1" }, { "binary_name": "libjs-dojo-dijit", "binary_version": "1.10.4+dfsg-2ubuntu0.1~esm1" }, { "binary_name": "libjs-dojo-dojox", "binary_version": "1.10.4+dfsg-2ubuntu0.1~esm1" } ], "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro" }