All 4 CVE vulnerabilities found in vue-i18n, with AI-generated Chinese analysis, references, and POCs.
Vendor: intlify
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-53892 | Intlify Vue I18n's escapeParameterHtml does not prevent DOM-based XSS via tag attributes like onerror CWE-79 | 6.1AI | MediumAI | 2025-07-16 |
| CVE-2025-27597 | Vue I18n Prototype Pollution in `handleFlatJson` CWE-1321 | 9.8 | - | 2025-03-07 |
| CVE-2024-52810 | Prototype Pollution in @intlify/shared >=9.7.0 <= 10.0.4 CWE-1321 | 9.1 | - | 2024-11-29 |
| CVE-2024-52809 | Cross-site Scripting vulnerability with prototype pollution in vue-i18n CWE-79 | 6.1 | - | 2024-11-29 |
All 4 known CVE vulnerabilities affecting vue-i18n with full Chinese analysis, references, and POCs where available.