The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
We have discovered 239,584 live websites that are affected by CVE-2021-23358.
Product | |
Category | JavaScript Libraries |
Vulnerable Domains | 239,584 live websites (12.68% of underscore install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 41 versions ( 82.00% of all versions) |
![]() | 82,063 websites |
![]() | 24,141 websites |
![]() | 15,212 websites |
![]() | 11,394 websites |
![]() | 7,962 websites |
![]() | 7,429 websites |
![]() | 7,087 websites |
![]() | 6,574 websites |
![]() | 5,916 websites |
![]() | 5,747 websites |
.com | 105,698 websites |
.org | 11,012 websites |
.de | 10,498 websites |
.net | 6,286 websites |
.nl | 6,202 websites |
.ru | 6,183 websites |
.co.uk | 6,131 websites |
.it | 5,452 websites |
.fr | 5,378 websites |
.pl | 4,772 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.com | ![]() | *** | |
************.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
********.com | ![]() | *,*** | |
***.com | ![]() | *,*** | |
******.com | ![]() | *,*** | |
*************.com | ![]() | *,*** | |
**********.org | ![]() | *,*** | |
************.com | ![]() | *,*** |
FAQ