GHSA-3657-q433-mmpx
GitHub Security Advisory
Canvs Canvas Cross-site Scripting (XSS) via title and content fields
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a "Posts > Add New" action, and during creation of new tags and users.
Affected Packages
Packagist
austintoddj/canvas
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 1, 2025 6:32 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.