Skip to main content
Loading…
    CVE-2026-3884 — Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An atta — CVE Database · The Intelligence Room