Total
5 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-22809 | 1 Amauri | 1 Tarteaucitronjs | 2026-01-20 | N/A | 4.4 MEDIUM |
|
tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.29.0, a Regular Expression Denial of Service (ReDoS) vulnerability was identified in tarteaucitron.js in the handling of the issuu_id parameter. This vulnerability is fixed in 1.29.0.
|
|||||
| CVE-2025-31475 | 1 Amauri | 1 Tarteaucitronjs | 2025-10-21 | N/A | 5.5 MEDIUM |
|
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the site's source code or a CMS plugin to manipulate JavaScript object prototypes, leading to potential security risks such as data corruption or unintended code execution. An attacker with high privileges could exploit this v ...
Show More |
|||||
| CVE-2025-48939 | 1 Amauri | 1 Tarteaucitronjs | 2025-10-21 | N/A | 4.2 MEDIUM |
|
tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that it referenced an actual <script> element. If an attacker injected an HTML element, it could clobber the document.currentScript property. This causes the script to resolve incorrectly to an element instead of the <script> tag, leading to unexpected behavior or failure to load the script path corre ...
Show More |
|||||
| CVE-2025-31138 | 1 Amauri | 1 Tarteaucitronjs | 2025-10-21 | N/A | 5.5 MEDIUM |
|
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker with direct access to the site's source code or a CMS plugin to set values like 100%;height:100%;position:fixed;, potentially covering the entire viewport and facilitating clickjacking attacks. An attacker with high privileges could exploit this ...
Show More |
|||||
| CVE-2025-31476 | 2 Amauri, Tacjs Project | 2 Tarteaucitronjs, Tacjs | 2025-09-04 | N/A | 4.8 MEDIUM |
|
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link. An attacker with high privileges could insert a link exploiting an insecure URL scheme, ...
Show More |
|||||