Loading HuntDB...

GHSA-crh5-vv2v-c82q

GitHub Security Advisory

@claviska/jquery-minicolors vulnerable to Cross-site Scripting

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

jQuery MiniColors is a color picker built on jQuery. Prior to version 2.3.6, jQuery MiniColors is prone to cross-site scripting when handling untrusted color names. This issue is patched in version 2.3.6.

Affected Packages

npm @claviska/jquery-minicolors
Affected versions: 0 (fixed in 2.3.6)

Related CVEs

Key Information

GHSA ID
GHSA-crh5-vv2v-c82q
Published
February 21, 2023 12:30 AM
Last Modified
February 22, 2023 12:09 AM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
@claviska/jquery-minicolors
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 9, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.