VDB
Sign up
MEDIUM

GHSA-gxp8-m5rq-3m38

QGIS QWC2 Cross-Site Scripting vulnerability

Quick fix

GHSA-gxp8-m5rq-3m38 — qwc2: upgrade to the fixed version with the command below.

npm install qwc2@2025.08.14

Details

Cross-Site Scripting vulnerability in attribute table in QGIS QWC2 < 2025.08.14 allows an authorized attacker to plant arbitrary JavaScript code in the page.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/qwc2
Introduced in: 0Fixed in: 2025.08.14
Fixnpm install qwc2@2025.08.14

References