Skip to content
Noroxi

postcss records

5 published records for vendor postcss.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

5 records
  • PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

    CriticalCVSS 9.1No exploitEPSS 1%

    postcss · postcssJul 27, 2026

  • Regular Expression Denial of Service (ReDoS)

    HighCVSS 7.5No exploitEPSS 3%

    postcss · postcssApr 26, 2021

  • PostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset

    MediumCVSS 6.3No exploitEPSS 0%

    postcss · postcssAug 3, 2026

  • Regular Expression Denial of Service (ReDoS)

    MediumCVSS 5.3No exploitEPSS 4%

    postcss · postcssApr 12, 2021

  • An issue was discovered in PostCSS before 8.4.31.

    MediumCVSS 5.3No exploitEPSS 1%

    postcss · postcssSep 29, 2023