Cross-Site Scripting Vulnerability in Nice-Select2 by Bluzky
CVE-2026-17528
5.3MEDIUM
What is CVE-2026-17528?
The Nice-Select2 library, prior to version 2.4.1, has a vulnerability that allows attackers to exploit Cross-Site Scripting (XSS) through the element. This arises when malicious scripts are improperly embedded within the DOM, leading to arbitrary script execution in the browser of users interacting with the vulnerable page. Users can be manipulated into executing harmful scripts without their consent, potentially exposing sensitive information or allowing unauthorized actions.
Affected Version(s)
nice-select2 0 < 2.4.1
