Description
mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.
Remediation
References
Related Vulnerabilities
WordPress Plugin Tapfiliate Cross-Site Scripting (3.0.12)
SharePoint Use After Free Vulnerability (CVE-2025-59222)
WordPress Plugin Import and export users and customers CSV Injection (1.16.3.5)
WordPress Plugin Controlled Admin Access Security Bypass (1.4.0)
WordPress Plugin WordPress Video Player Multiple SQL Injection Vulnerabilities (1.5.16)