Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestion detail

Untriaged
created 5 days, 3 hours ago Activity log
  • Created suggestion
Visualizer < 4.0.8 - Contributor+ Stored XSS via JSON Data Source

The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any higher-privileged user, such as an administrator, who reviews the affected chart.

References

Affected products

Visualizer
  • <4.0.8

Matching in nixpkgs

pkgs.dbvisualizer

Universal database tool

  • nixos-unstable -
  • nixos-26.05 -

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

pkgs.ttnn-visualizer

Tool for visualizing and analyzing TT-NN model execution

  • nixos-unstable -
    • nixos-unstable-small

pkgs.pulse-visualizer

Real-time audio visualizer inspired by MiniMeters

  • nixos-unstable -
    • nixos-unstable-small 1.3.9
  • nixos-26.05 -
    • nixos-26.05-small 1.3.9

pkgs.pkgsRocm.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3