{"id":"CVE-2024-34449","aliases":["GHSA-m5jf-8crm-r65m"],"url":"https://o3.security/vulnerability/CVE-2024-34449","summary":"Vditor allows Cross-site Scripting via an attribute of an `A` element","details":"Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.","published":"2024-05-03T00:00:00Z","modified":"2026-08-12T03:51:16.437118114Z","cvss":null,"epss":{"score":0.00359,"percentile":0.28849,"asOf":"2026-09-01"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"vditor","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Vanessa219/vditor/blob/b3a14d6e4462b0c17141e1fcc66173264ada64e0/README_en_US.md?plain=1#L310"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/34xxx/CVE-2024-34449.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34449"},{"type":"REPORT","url":"https://github.com/Vanessa219/vditor/issues/1604"},{"type":"PACKAGE","url":"https://github.com/Vanessa219/vditor"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.437118114Z"}}