The Validator Project develops a focused validation library whose modest footprint in the vulnerability landscape masks its importance as a common dependency in web applications and data-processing pipelines. The recurring weakness classes—encoding errors, cross-site scripting, input-filtering gaps, and regular-expression complexity—reflect the core parsing and sanitization demands of validation logic, where subtle flaws in character handling or pattern matching can propagate through downstream code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Validator Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12758HIGH Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take | Nov 27, 2025 | 7.5 | 28 | NO | NO |
CVE-2021-3765HIGH validator.js is vulnerable to Inefficient Regular Expression Complexity | Nov 2, 2021 | 7.5 | 25 | NO | NO |
CVE-2025-56200MEDIUM A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as | Sep 30, 2025 | 6.1 | 24 | NO | NO |
CVE-2025-15104MEDIUM Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including | Jan 16, 2026 | 5.3 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Validator Project.
Media articles that mention a CVE ID that affects a product developed by Validator Project — matched by CVE ID, not by vendor name.