MEDIUM
GHSA-gxp8-m5rq-3m38
QGIS QWC2 Cross-Site Scripting vulnerability
Quick fix
GHSA-gxp8-m5rq-3m38 — qwc2: upgrade to the fixed version with the command below.
npm install qwc2@2025.08.14Details
Cross-Site Scripting vulnerability in attribute table in QGIS QWC2 < 2025.08.14 allows an authorized attacker to plant arbitrary JavaScript code in the page.
Are you affected?
Enter the version of the package you're using.