spin.js CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

spin.js vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to spin.js, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-3884 Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an arbitrary key-value pair on Object.prototype through a crafted URL achieving a prototype pollution first, before being able to execute arbitrary JavaScript in the context of the user's browser. [email protected] 2.0 0.16% 2026-03-11 2026-05-07
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence