nuget package report

Is org.webjars.bowergithub.vaadin:vaadin-menu-bar safe?

1 known vulnerability, worst severity MODERATE.

cvss
6.1

how bad it is if exploited, out of 10

epss
1.0%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-93c4-vf86-3rj7, the advisory selected below

// advisories

GHSA-93c4-vf86-3rj7

MODERATECVE-2021-33611

Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.4.4) allows remote attackers to execute malicious JavaScript in browser by opening crafted URL.

Affected
>= 1.0.0, <= 1.2.0
Fixed in
1.2.1
Published
2021-11-03
Source
github

GHSANVDMITREreferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so nuget packages are not covered.


Checked 2026-09-22 at 01:50 UTC. The most recent advisory here was published 2021-11-03. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.webjars.bowergithub.vaadin:vaadin-menu-bar safe? nuget package security report | CyberXYZ