Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-79320 | 1 Stenciljs | 1 Core | 2026-09-29 | 6.1 Medium |
| Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downstream application enables the experimental slot fixes option and uses scoped components, assigning a string to the textContent property of such a component's host element causes the value to be parsed as HTML instead of being inserted as text. If an application writes attacker-controlled data to these host elements, the data can be interpreted as markup and script can execute in the context of the application's origin. | ||||
| CVE-2026-79319 | 1 Stenciljs | 1 Core | 2026-09-29 | 5.3 Medium |
| Stencil core 4.43.5 is vulnerable to Incorrect Access Control. | ||||
Page 1 of 1.