Select2 is a JavaScript library for enhancing HTML select elements with search, filtering, and tagging functionality, and its vulnerability exposure centers on cross-site scripting risks in its web-facing input handling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Select2 over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10744MEDIUM In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to d | Mar 27, 2019 | 6.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Select2.
Media articles that mention a CVE ID that affects a product developed by Select2 — matched by CVE ID, not by vendor name.