Baguettebox.js is a lightweight JavaScript library for image gallery and lightbox functionality, with a vulnerability profile centered on its single product implementation. The observed weakness class reflects input-handling issues in web-facing contexts, specifically improper neutralization during page generation that can lead to cross-site scripting. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Baguettebox.Js Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3733MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).This issue affects bag | Apr 16, 2025 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Baguettebox.Js Project.
Media articles that mention a CVE ID that affects a product developed by Baguettebox.Js Project — matched by CVE ID, not by vendor name.