This issue affects Vuetify versions greater than or equal to 2.0.0 and less than 3.0.0.
Note:
Version 2.x of Vuetify is End-of-Life and will not receive any updates to address this issue. For more information see here https://v2.vuetifyjs.com/en/about/eol/ .
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9w3x-85mw-4fwm | Vuetify has a Cross-site Scripting (XSS) vulnerability in the VDatePicker component |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 17 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vuetifyjs
Vuetifyjs vuetify |
|
| Vendors & Products |
Vuetifyjs
Vuetifyjs vuetify |
Fri, 12 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inserted into the page. This can lead to a Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss attack. The vulnerability occurs because the 'title-date-format' property of the 'VDatePicker' can accept a user created function and assign its output to the 'innerHTML' property of the title element without sanitization. This issue affects Vuetify versions greater than or equal to 2.0.0 and less than 3.0.0. Note: Version 2.x of Vuetify is End-of-Life and will not receive any updates to address this issue. For more information see here https://v2.vuetifyjs.com/en/about/eol/ . | |
| Title | Vuetify XSS via unsanitized 'titleDateFormat' in 'VDatePicker' | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HeroDevs
Published:
Updated: 2025-12-12T19:08:54.180Z
Reserved: 2025-07-23T13:08:25.958Z
Link: CVE-2025-8082
Updated: 2025-12-12T19:08:50.336Z
Status : Awaiting Analysis
Published: 2025-12-12T19:16:04.097
Modified: 2025-12-15T18:22:40.637
Link: CVE-2025-8082
OpenCVE Enrichment
Updated: 2025-12-14T21:16:05Z
Github GHSA