{ "schema_version": "1.4.0", "id": "GHSA-2j2j-8rrv-264g", "modified": "2023-09-13T18:50:53Z", "published": "2018-09-11T18:58:40Z", "aliases": [ "CVE-2018-16459" ], "summary": "Cross-Site Scripting in exceljs", "details": "Versions of `exceljs` before 1.6.0 are vulnerable to cross-site scripting. \n\nThis vulnerability is due to `exceljs` not validating data from parsed XLSX file and embedding HTML tags, like `