<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Vuetify</title>
  <link>https://cvedaily.com/pages/tags/vuetify.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/vuetify.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Vuetify</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:03 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-8083 – The  Preset configuration https://v2.vuetifyjs.com/en/features/presets  feature ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8083</guid>
    <pubDate>Fri, 12 Dec 2025 20:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8083</strong></p>
  <p>The  Preset configuration https://v2.vuetifyjs.com/en/features/presets  feature of Vuetify is vulnerable to  Prototype Pollution https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html  due to the internal 'mergeDeep' utility function used to merge options with defaults. Using a specially-crafted, malicious preset can result in polluting all JavaScript objec…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8082 – Improper neutralization of the title date in the 'VDatePicker' component in Vuet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8082</guid>
    <pubDate>Fri, 12 Dec 2025 19:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8082</strong></p>
  <p>Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inserted into the page. This can lead to a  Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss  attack. The vulnerability occurs because the 'title-date-format' property of the 'VDatePicker' can accept a user created function and assign its output to the 'innerHTM…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-1461 – Improper neutralization of the value of the 'eventMoreText' property of the 'VCa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1461</guid>
    <pubDate>Wed, 28 May 2025 18:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-1461</strong></p>
  <p>Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component in Vuetify allows unsanitized HTML to be inserted into the page. This can lead to a  Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss  attack. The vulnerability occurs because the default Vuetify translator will return the translation key as the translation, if it can't find an…</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-25873 – The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25873</guid>
    <pubDate>Sun, 18 Sep 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-25873</strong></p>
  <p>The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25873">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
