Vulnerabilities > Post Loader Project

DATE CVE VULNERABILITY TITLE RISK
2022-03-17 CVE-2022-0748 Cross-site Scripting vulnerability in Post-Loader Project Post-Loader
The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.
network
low complexity
post-loader-project CWE-79
critical
9.8