Validator is a narrowly scoped tool or library focused on input validation, with a vulnerability footprint concentrated in a single product bearing the same name. The durable signal centers on server-side request forgery (SSRF) weaknesses, reflecting the validation logic's exposure to remote-origin control. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Validator over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12758HIGH Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take | Nov 27, 2025 | 7.5 | 28 | NO | NO |
CVE-2021-3765HIGH validator.js is vulnerable to Inefficient Regular Expression Complexity | Nov 2, 2021 | 7.5 | 25 | NO | NO |
CVE-2025-56200MEDIUM A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as | Sep 30, 2025 | 6.1 | 24 | NO | NO |
CVE-2025-15104MEDIUM Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including | Jan 16, 2026 | 5.3 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Validator.
Media articles that mention a CVE ID that affects a product developed by Validator — matched by CVE ID, not by vendor name.