Filtered by vendor Bluzky Subscriptions
Filtered by product Nice-select2 Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-17528 1 Bluzky 1 Nice-select2 2026-08-03 6.1 Medium
Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a victim’s browser when they view or interact with the affected page.