Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21704 | vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes |
Github GHSA |
GHSA-x8qp-wqqm-57ph | vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes |
Tue, 22 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.14.5, 10.0.8, and 11.1.0, this setting fails to prevent execution of certain tag-based payloads, such as <img src=x onerror=...>, if the interpolated value is inserted inside an HTML context using v-html. This may lead to a DOM-based XSS vulnerability, even when using escapeParameterHtml: true, if a translation string includes minor HTML and is rendered via v-html. Versions 9.14.5, 10.0.8, and 11.1.0 contain a fix for the issue. | |
| Title | Intlify Vue I18n's escapeParameterHtml does not prevent DOM-based XSS via tag attributes like onerror | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-22T14:58:34.382Z
Reserved: 2025-07-11T19:05:23.825Z
Link: CVE-2025-53892
Updated: 2025-07-22T14:57:58.777Z
Status : Deferred
Published: 2025-07-16T14:15:28.357
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-53892
No data.
OpenCVE Enrichment
Updated: 2025-07-21T15:17:21Z
EUVD
Github GHSA