{"id":"CVE-2020-28487","aliases":["GHSA-9mrv-456v-pf22"],"url":"https://o3.security/vulnerability/CVE-2020-28487","summary":"Cross-site Scripting in vis-timeline","details":"This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.","published":"2021-01-22T18:15:12.517Z","modified":"2026-07-08T20:43:38.169684Z","cvss":{"score":6.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"vis-timeline","fixedVersion":"7.4.4"}],"fix":{"url":"https://github.com/visjs/vis-timeline/pull/840","label":"visjs/vis-timeline#840"},"references":[{"type":"REPORT","url":"https://github.com/visjs/vis-timeline/issues/838"},{"type":"FIX","url":"https://github.com/visjs/vis-timeline/pull/840"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBVISJS-1063502"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1063501"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JS-VISTIMELINE-1063500"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:43:38.169684Z"}}