VendorsAmauritarteaucitronjsall versions
Vulnerabilities

Amauri tarteaucitronjs (tarteaucitron)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2025-31475
tarteaucitron.js allows prototype pollution via custom text injection
Published 2025-04-07 · Analyzed
6.6EPSS 0.003
CVE-2025-31138
tarteaucitron.js allows UI manipulation via unrestricted CSS injection
Published 2025-04-07 · Analyzed
6.6EPSS 0.003
CVE-2025-31476
tarteaucitron.js allows url scheme injection via unfiltered inputs
Published 2025-04-07 · Analyzed
4.8EPSS 0.004
CVE-2026-22809
tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability
Published 2026-01-13 · Analyzed
4.4EPSS 0.001
CVE-2025-48939
tarteaucitron.js vulnerable to DOM Clobbering via document.currentScript
Published 2025-07-03 · Analyzed
4.2EPSS 0.002