HIGH8.7npm
GHSA-xhq9-whgq-49j5· CVE-2026-63459Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
Modified: 9/17/2026
package
pkg:npm/%40vendure/dashboard
Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
Modified: 9/17/2026