In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was identified in an IP Reputation Checker application. Unsanitized user input was directly rendered in the browser, allowing attackers to execute arbitrary JavaScript. This issue has been patched in version 2.0.1.
Metrics
Affected Vendors & Products
References
History
Fri, 08 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was identified in an IP Reputation Checker application. Unsanitized user input was directly rendered in the browser, allowing attackers to execute arbitrary JavaScript. This issue has been patched in version 2.0.1. | |
| Title | th30d4y/IP: DOM-Based Cross-Site Scripting (XSS) Vulnerability | |
| Weaknesses | CWE-79 CWE-80 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T16:41:23.602Z
Reserved: 2026-04-21T14:15:21.958Z
Link: CVE-2026-41575
Updated: 2026-05-08T16:36:38.268Z
Status : Awaiting Analysis
Published: 2026-05-08T15:16:40.740
Modified: 2026-05-08T16:08:15.570
Link: CVE-2026-41575
No data.
OpenCVE Enrichment
Updated: 2026-05-08T18:00:16Z