Reveal.js is a web-based presentation framework whose vulnerability profile centers on client-side input handling in its core library. The observed weakness class reflects the framework's role in rendering user-controlled presentation content, with cross-site scripting representing the primary attack surface where proper input sanitization is critical. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Revealjs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0776MEDIUM Cross-site Scripting (XSS) - DOM in GitHub repository hakimel/reveal.js prior to 4.3.0. | Mar 1, 2022 | 6.1 | 33 | NO | YES |
CVE-2020-8127MEDIUM Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attackers to perform cross-site scripting attacks. | Feb 28, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Revealjs.
Media articles that mention a CVE ID that affects a product developed by Revealjs — matched by CVE ID, not by vendor name.