Browse all 6 CVE security advisories affecting flavorjones. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Flavorjones develops web application frameworks and libraries, primarily for building dynamic web services. Historically, vulnerabilities associated with this developer include remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation failures and insecure default configurations. While no major public security incidents have been documented, the three CVEs on record highlight recurring issues in sanitizing user inputs and managing access controls. The codebase typically requires careful configuration to mitigate risks, particularly in environments handling untrusted data or multi-user access scenarios.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-73492 | Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons — loofah CWE-79 | 2.3 | Low | 2026-08-12 |
| CVE-2026-73491 | Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references — loofah CWE-184 | 2.3 | Low | 2026-08-12 |
| CVE-2026-73490 | Loofah: SVG `href` attribute bypasses local-reference restriction — loofah CWE-79 | 4.7 | Medium | 2026-08-12 |
| CVE-2022-23516 | Uncontrolled Recursion in Loofah — loofah CWE-674 | 7.5 | High | 2022-12-14 |
| CVE-2022-23515 | Improper neutralization of data URIs may allow XSS in Loofah — loofah CWE-79 | 6.1 | Medium | 2022-12-14 |
| CVE-2022-23514 | Inefficient Regular Expression Complexity in Loofah — loofah CWE-1333 | 7.5 | High | 2022-12-14 |
This page lists every published CVE security advisory associated with flavorjones. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.