CVE-2026-1513: XSS
Published Jan 28, 2026
·Updated
billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.
Affected Software
3 affected componentsFixes available
npm/billboard.js<3.18.0
npm/billboard.js<3.18.0
3.18.0
NAVER Billboard.js<3.18.0
Event History
Jan 28, 2026
CVE Published
via MITRE·01:28 AM
Data Sourced
via MITRE·01:28 AM
DescriptionWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 AM
Data Sourced
via GitHub·03:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-1513?
CVE-2026-1513 is a high severity vulnerability due to the potential for malicious JavaScript execution.
2
How do I fix CVE-2026-1513?
To fix CVE-2026-1513, upgrade billboard.js to version 3.18.0 or later.
3
What causes CVE-2026-1513?
CVE-2026-1513 is caused by improper sanitization during chart option binding in billboard.js versions prior to 3.18.0.
4
Who is affected by CVE-2026-1513?
Any application using billboard.js versions before 3.18.0 is affected by CVE-2026-1513.
5
What are the potential impacts of CVE-2026-1513?
The potential impacts of CVE-2026-1513 include the execution of arbitrary JavaScript code, which could lead to data theft or site compromise.