@@ -432,6 +432,26 @@ nodes
432432| trusted-types.js:2:71:2:71 | x |
433433| trusted-types.js:3:24:3:34 | window.name |
434434| trusted-types.js:3:24:3:34 | window.name |
435+ | tst3.js:2:12:2:75 | JSON.pa ... tr(1))) |
436+ | tst3.js:2:23:2:74 | decodeU ... str(1)) |
437+ | tst3.js:2:42:2:63 | window. ... .search |
438+ | tst3.js:2:42:2:63 | window. ... .search |
439+ | tst3.js:2:42:2:73 | window. ... bstr(1) |
440+ | tst3.js:4:25:4:28 | data |
441+ | tst3.js:4:25:4:32 | data.src |
442+ | tst3.js:4:25:4:32 | data.src |
443+ | tst3.js:5:26:5:29 | data |
444+ | tst3.js:5:26:5:31 | data.p |
445+ | tst3.js:5:26:5:31 | data.p |
446+ | tst3.js:7:32:7:35 | data |
447+ | tst3.js:7:32:7:37 | data.p |
448+ | tst3.js:7:32:7:37 | data.p |
449+ | tst3.js:9:37:9:40 | data |
450+ | tst3.js:9:37:9:42 | data.p |
451+ | tst3.js:9:37:9:42 | data.p |
452+ | tst3.js:10:38:10:41 | data |
453+ | tst3.js:10:38:10:43 | data.p |
454+ | tst3.js:10:38:10:43 | data.p |
435455| tst.js:2:7:2:39 | target |
436456| tst.js:2:7:2:39 | target |
437457| tst.js:2:16:2:39 | documen ... .search |
@@ -732,6 +752,29 @@ nodes
732752| tst.js:465:19:465:24 | source |
733753| tst.js:467:20:467:25 | source |
734754| tst.js:467:20:467:25 | source |
755+ | tst.js:471:7:471:46 | url |
756+ | tst.js:471:13:471:36 | documen ... .search |
757+ | tst.js:471:13:471:36 | documen ... .search |
758+ | tst.js:471:13:471:46 | documen ... bstr(1) |
759+ | tst.js:473:19:473:21 | url |
760+ | tst.js:473:19:473:21 | url |
761+ | tst.js:474:26:474:28 | url |
762+ | tst.js:474:26:474:28 | url |
763+ | tst.js:475:25:475:27 | url |
764+ | tst.js:475:25:475:27 | url |
765+ | tst.js:476:20:476:22 | url |
766+ | tst.js:476:20:476:22 | url |
767+ | tst.js:479:20:479:45 | "http:/ ... " + url |
768+ | tst.js:479:20:479:45 | "http:/ ... " + url |
769+ | tst.js:479:43:479:45 | url |
770+ | tst.js:481:20:481:45 | ["http: ... ", url] |
771+ | tst.js:481:20:481:55 | ["http: ... in("/") |
772+ | tst.js:481:20:481:55 | ["http: ... in("/") |
773+ | tst.js:481:42:481:44 | url |
774+ | tst.js:484:22:484:24 | url |
775+ | tst.js:484:22:484:24 | url |
776+ | tst.js:486:22:486:24 | url |
777+ | tst.js:486:22:486:24 | url |
735778| typeahead.js:20:13:20:45 | target |
736779| typeahead.js:20:22:20:45 | documen ... .search |
737780| typeahead.js:20:22:20:45 | documen ... .search |
@@ -1172,6 +1215,25 @@ edges
11721215| trusted-types.js:2:66:2:66 | x | trusted-types.js:2:71:2:71 | x |
11731216| trusted-types.js:3:24:3:34 | window.name | trusted-types.js:2:66:2:66 | x |
11741217| trusted-types.js:3:24:3:34 | window.name | trusted-types.js:2:66:2:66 | x |
1218+ | tst3.js:2:12:2:75 | JSON.pa ... tr(1))) | tst3.js:4:25:4:28 | data |
1219+ | tst3.js:2:12:2:75 | JSON.pa ... tr(1))) | tst3.js:5:26:5:29 | data |
1220+ | tst3.js:2:12:2:75 | JSON.pa ... tr(1))) | tst3.js:7:32:7:35 | data |
1221+ | tst3.js:2:12:2:75 | JSON.pa ... tr(1))) | tst3.js:9:37:9:40 | data |
1222+ | tst3.js:2:12:2:75 | JSON.pa ... tr(1))) | tst3.js:10:38:10:41 | data |
1223+ | tst3.js:2:23:2:74 | decodeU ... str(1)) | tst3.js:2:12:2:75 | JSON.pa ... tr(1))) |
1224+ | tst3.js:2:42:2:63 | window. ... .search | tst3.js:2:42:2:73 | window. ... bstr(1) |
1225+ | tst3.js:2:42:2:63 | window. ... .search | tst3.js:2:42:2:73 | window. ... bstr(1) |
1226+ | tst3.js:2:42:2:73 | window. ... bstr(1) | tst3.js:2:23:2:74 | decodeU ... str(1)) |
1227+ | tst3.js:4:25:4:28 | data | tst3.js:4:25:4:32 | data.src |
1228+ | tst3.js:4:25:4:28 | data | tst3.js:4:25:4:32 | data.src |
1229+ | tst3.js:5:26:5:29 | data | tst3.js:5:26:5:31 | data.p |
1230+ | tst3.js:5:26:5:29 | data | tst3.js:5:26:5:31 | data.p |
1231+ | tst3.js:7:32:7:35 | data | tst3.js:7:32:7:37 | data.p |
1232+ | tst3.js:7:32:7:35 | data | tst3.js:7:32:7:37 | data.p |
1233+ | tst3.js:9:37:9:40 | data | tst3.js:9:37:9:42 | data.p |
1234+ | tst3.js:9:37:9:40 | data | tst3.js:9:37:9:42 | data.p |
1235+ | tst3.js:10:38:10:41 | data | tst3.js:10:38:10:43 | data.p |
1236+ | tst3.js:10:38:10:41 | data | tst3.js:10:38:10:43 | data.p |
11751237| tst.js:2:7:2:39 | target | tst.js:5:18:5:23 | target |
11761238| tst.js:2:7:2:39 | target | tst.js:5:18:5:23 | target |
11771239| tst.js:2:7:2:39 | target | tst.js:12:28:12:33 | target |
@@ -1426,6 +1488,28 @@ edges
14261488| tst.js:460:6:460:38 | source | tst.js:467:20:467:25 | source |
14271489| tst.js:460:15:460:38 | documen ... .search | tst.js:460:6:460:38 | source |
14281490| tst.js:460:15:460:38 | documen ... .search | tst.js:460:6:460:38 | source |
1491+ | tst.js:471:7:471:46 | url | tst.js:473:19:473:21 | url |
1492+ | tst.js:471:7:471:46 | url | tst.js:473:19:473:21 | url |
1493+ | tst.js:471:7:471:46 | url | tst.js:474:26:474:28 | url |
1494+ | tst.js:471:7:471:46 | url | tst.js:474:26:474:28 | url |
1495+ | tst.js:471:7:471:46 | url | tst.js:475:25:475:27 | url |
1496+ | tst.js:471:7:471:46 | url | tst.js:475:25:475:27 | url |
1497+ | tst.js:471:7:471:46 | url | tst.js:476:20:476:22 | url |
1498+ | tst.js:471:7:471:46 | url | tst.js:476:20:476:22 | url |
1499+ | tst.js:471:7:471:46 | url | tst.js:479:43:479:45 | url |
1500+ | tst.js:471:7:471:46 | url | tst.js:481:42:481:44 | url |
1501+ | tst.js:471:7:471:46 | url | tst.js:484:22:484:24 | url |
1502+ | tst.js:471:7:471:46 | url | tst.js:484:22:484:24 | url |
1503+ | tst.js:471:7:471:46 | url | tst.js:486:22:486:24 | url |
1504+ | tst.js:471:7:471:46 | url | tst.js:486:22:486:24 | url |
1505+ | tst.js:471:13:471:36 | documen ... .search | tst.js:471:13:471:46 | documen ... bstr(1) |
1506+ | tst.js:471:13:471:36 | documen ... .search | tst.js:471:13:471:46 | documen ... bstr(1) |
1507+ | tst.js:471:13:471:46 | documen ... bstr(1) | tst.js:471:7:471:46 | url |
1508+ | tst.js:479:43:479:45 | url | tst.js:479:20:479:45 | "http:/ ... " + url |
1509+ | tst.js:479:43:479:45 | url | tst.js:479:20:479:45 | "http:/ ... " + url |
1510+ | tst.js:481:20:481:45 | ["http: ... ", url] | tst.js:481:20:481:55 | ["http: ... in("/") |
1511+ | tst.js:481:20:481:45 | ["http: ... ", url] | tst.js:481:20:481:55 | ["http: ... in("/") |
1512+ | tst.js:481:42:481:44 | url | tst.js:481:20:481:45 | ["http: ... ", url] |
14291513| typeahead.js:20:13:20:45 | target | typeahead.js:21:12:21:17 | target |
14301514| typeahead.js:20:22:20:45 | documen ... .search | typeahead.js:20:13:20:45 | target |
14311515| typeahead.js:20:22:20:45 | documen ... .search | typeahead.js:20:13:20:45 | target |
@@ -1583,6 +1667,11 @@ edges
15831667| tooltip.jsx:11:25:11:30 | source | tooltip.jsx:6:20:6:30 | window.name | tooltip.jsx:11:25:11:30 | source | Cross-site scripting vulnerability due to $@. | tooltip.jsx:6:20:6:30 | window.name | user-provided value |
15841668| translate.js:9:27:9:50 | searchP ... 'term') | translate.js:6:16:6:39 | documen ... .search | translate.js:9:27:9:50 | searchP ... 'term') | Cross-site scripting vulnerability due to $@. | translate.js:6:16:6:39 | documen ... .search | user-provided value |
15851669| trusted-types.js:2:71:2:71 | x | trusted-types.js:3:24:3:34 | window.name | trusted-types.js:2:71:2:71 | x | Cross-site scripting vulnerability due to $@. | trusted-types.js:3:24:3:34 | window.name | user-provided value |
1670+ | tst3.js:4:25:4:32 | data.src | tst3.js:2:42:2:63 | window. ... .search | tst3.js:4:25:4:32 | data.src | Cross-site scripting vulnerability due to $@. | tst3.js:2:42:2:63 | window. ... .search | user-provided value |
1671+ | tst3.js:5:26:5:31 | data.p | tst3.js:2:42:2:63 | window. ... .search | tst3.js:5:26:5:31 | data.p | Cross-site scripting vulnerability due to $@. | tst3.js:2:42:2:63 | window. ... .search | user-provided value |
1672+ | tst3.js:7:32:7:37 | data.p | tst3.js:2:42:2:63 | window. ... .search | tst3.js:7:32:7:37 | data.p | Cross-site scripting vulnerability due to $@. | tst3.js:2:42:2:63 | window. ... .search | user-provided value |
1673+ | tst3.js:9:37:9:42 | data.p | tst3.js:2:42:2:63 | window. ... .search | tst3.js:9:37:9:42 | data.p | Cross-site scripting vulnerability due to $@. | tst3.js:2:42:2:63 | window. ... .search | user-provided value |
1674+ | tst3.js:10:38:10:43 | data.p | tst3.js:2:42:2:63 | window. ... .search | tst3.js:10:38:10:43 | data.p | Cross-site scripting vulnerability due to $@. | tst3.js:2:42:2:63 | window. ... .search | user-provided value |
15861675| tst.js:5:18:5:23 | target | tst.js:2:16:2:39 | documen ... .search | tst.js:5:18:5:23 | target | Cross-site scripting vulnerability due to $@. | tst.js:2:16:2:39 | documen ... .search | user-provided value |
15871676| tst.js:8:18:8:126 | "<OPTIO ... PTION>" | tst.js:8:37:8:58 | documen ... on.href | tst.js:8:18:8:126 | "<OPTIO ... PTION>" | Cross-site scripting vulnerability due to $@. | tst.js:8:37:8:58 | documen ... on.href | user-provided value |
15881677| tst.js:12:5:12:42 | '<div s ... 'px">' | tst.js:2:16:2:39 | documen ... .search | tst.js:12:5:12:42 | '<div s ... 'px">' | Cross-site scripting vulnerability due to $@. | tst.js:2:16:2:39 | documen ... .search | user-provided value |
@@ -1665,6 +1754,14 @@ edges
16651754| tst.js:463:21:463:26 | source | tst.js:460:15:460:38 | documen ... .search | tst.js:463:21:463:26 | source | Cross-site scripting vulnerability due to $@. | tst.js:460:15:460:38 | documen ... .search | user-provided value |
16661755| tst.js:465:19:465:24 | source | tst.js:460:15:460:38 | documen ... .search | tst.js:465:19:465:24 | source | Cross-site scripting vulnerability due to $@. | tst.js:460:15:460:38 | documen ... .search | user-provided value |
16671756| tst.js:467:20:467:25 | source | tst.js:460:15:460:38 | documen ... .search | tst.js:467:20:467:25 | source | Cross-site scripting vulnerability due to $@. | tst.js:460:15:460:38 | documen ... .search | user-provided value |
1757+ | tst.js:473:19:473:21 | url | tst.js:471:13:471:36 | documen ... .search | tst.js:473:19:473:21 | url | Cross-site scripting vulnerability due to $@. | tst.js:471:13:471:36 | documen ... .search | user-provided value |
1758+ | tst.js:474:26:474:28 | url | tst.js:471:13:471:36 | documen ... .search | tst.js:474:26:474:28 | url | Cross-site scripting vulnerability due to $@. | tst.js:471:13:471:36 | documen ... .search | user-provided value |
1759+ | tst.js:475:25:475:27 | url | tst.js:471:13:471:36 | documen ... .search | tst.js:475:25:475:27 | url | Cross-site scripting vulnerability due to $@. | tst.js:471:13:471:36 | documen ... .search | user-provided value |
1760+ | tst.js:476:20:476:22 | url | tst.js:471:13:471:36 | documen ... .search | tst.js:476:20:476:22 | url | Cross-site scripting vulnerability due to $@. | tst.js:471:13:471:36 | documen ... .search | user-provided value |
1761+ | tst.js:479:20:479:45 | "http:/ ... " + url | tst.js:471:13:471:36 | documen ... .search | tst.js:479:20:479:45 | "http:/ ... " + url | Cross-site scripting vulnerability due to $@. | tst.js:471:13:471:36 | documen ... .search | user-provided value |
1762+ | tst.js:481:20:481:55 | ["http: ... in("/") | tst.js:471:13:471:36 | documen ... .search | tst.js:481:20:481:55 | ["http: ... in("/") | Cross-site scripting vulnerability due to $@. | tst.js:471:13:471:36 | documen ... .search | user-provided value |
1763+ | tst.js:484:22:484:24 | url | tst.js:471:13:471:36 | documen ... .search | tst.js:484:22:484:24 | url | Cross-site scripting vulnerability due to $@. | tst.js:471:13:471:36 | documen ... .search | user-provided value |
1764+ | tst.js:486:22:486:24 | url | tst.js:471:13:471:36 | documen ... .search | tst.js:486:22:486:24 | url | Cross-site scripting vulnerability due to $@. | tst.js:471:13:471:36 | documen ... .search | user-provided value |
16681765| typeahead.js:25:18:25:20 | val | typeahead.js:20:22:20:45 | documen ... .search | typeahead.js:25:18:25:20 | val | Cross-site scripting vulnerability due to $@. | typeahead.js:20:22:20:45 | documen ... .search | user-provided value |
16691766| v-html.vue:2:8:2:23 | v-html=tainted | v-html.vue:6:42:6:58 | document.location | v-html.vue:2:8:2:23 | v-html=tainted | Cross-site scripting vulnerability due to $@. | v-html.vue:6:42:6:58 | document.location | user-provided value |
16701767| various-concat-obfuscations.js:4:4:4:31 | "<div>" ... </div>" | various-concat-obfuscations.js:2:16:2:39 | documen ... .search | various-concat-obfuscations.js:4:4:4:31 | "<div>" ... </div>" | Cross-site scripting vulnerability due to $@. | various-concat-obfuscations.js:2:16:2:39 | documen ... .search | user-provided value |
0 commit comments