Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1888 | A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. |
Github GHSA |
GHSA-2r57-2mrh-ggjv | ydata cross-site scripting |
| Link | Providers |
|---|---|
| https://hiddenlayer.com/sai-security-advisory/ydata-june2024 |
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2024-08-02T03:43:50.868Z
Reserved: 2024-05-31T14:19:09.798Z
Link: CVE-2024-37063
Updated: 2024-08-02T03:43:50.868Z
Status : Deferred
Published: 2024-06-04T12:15:13.110
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-37063
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA