hello.js_project CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

hello.js_project vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to hello.js_project, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-26505 Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function. [email protected] 9.8 0.95% 2023-08-11 2026-06-16
CVE-2020-7741 This affects the package hellojs before 1.18.6. The code get the param oauth_redirect from url and pass it to location.assign without any check and sanitisation. So we can simply pass some XSS payloads into the url param oauth_redirect, such as javascript:alert(1). [email protected] 9.9 1.46% 2020-10-06 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence