Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-106139 1 Progress 1 Kendo Ui For Vue 2026-10-11 5.4 Medium
In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.
CVE-2024-11628 1 Progress 1 Kendo Ui For Vue 2025-06-27 4.1 Medium
In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.