{"id":"CVE-2021-23445","aliases":["GHSA-h73q-5wmj-q8pj"],"url":"https://o3.security/vulnerability/CVE-2021-23445","summary":"Cross site scripting in datatables.net ","details":"This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.","published":"2021-09-27T17:15:08.137Z","modified":"2026-07-09T01:25:04.593517Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.01975,"percentile":0.78709,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"npm","name":"datatables.net","fixedVersion":"1.11.3"}],"fix":{"url":"https://github.com/DataTables/Dist-DataTables/commit/59a8d3f8a3c1138ab08704e783bc52bfe88d7c9b","label":"DataTables/Dist-DataTables@59a8d3f"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00018.html"},{"type":"ADVISORY","url":"https://cdn.datatables.net/1.11.3/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240621-0006/"},{"type":"FIX","url":"https://github.com/DataTables/Dist-DataTables/commit/59a8d3f8a3c1138ab08704e783bc52bfe88d7c9b"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1715371"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1715376"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1540544"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:25:04.593517Z"}}