9.8
CVSSv3

CVE-2025-49223

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00155 | KEV: Not Included
Published: 04/06/2025 Updated: 04/06/2025

Vulnerability Summary

Prototype Pollution Vulnerability in billboard.js Before Version 3.15.1

billboard.js prior to 3.15.1 exists to contain a prototype pollution via the function generate, which could allow malicious users to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

naver billboard.js

Github Repositories

CVE-2025-49223 - Prototype Pollution in Billboard.js

💥 CVE-2025-49223 - Prototype Pollution in Billboardjs billboardjs before 3151 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties This repository demonstrates a Prototype Pollution vulnerability found in billboardjs versio