{"id":"CVE-2021-23327","aliases":["GHSA-w46j-8hm6-h8mm"],"url":"https://o3.security/vulnerability/CVE-2021-23327","summary":"XSS in apexcharts","details":"The package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph legend fields.","published":"2021-02-09T08:15:11.167Z","modified":"2026-07-08T06:01:23.334207101Z","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"apexcharts","fixedVersion":"3.24.0"}],"fix":{"url":"https://github.com/apexcharts/apexcharts.js/commit/68f3f34d125719b4767614fe0a595cc65bde1d19","label":"apexcharts/apexcharts.js@68f3f34"},"references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1070616"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-APEXCHARTS-1062708"},{"type":"FIX","url":"https://github.com/apexcharts/apexcharts.js/commit/68f3f34d125719b4767614fe0a595cc65bde1d19"},{"type":"EVIDENCE","url":"https://github.com/apexcharts/apexcharts.js/pull/2158"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T06:01:23.334207101Z"}}