IA Squad
SearchPT

devbridge-autocomplete

js · devbridge-autocompleteHeads-up

devbridge-autocomplete: XSS via unescaped formatGroup and formatResult

The default `formatGroup` and `formatResult` functions concatenate values into HTML without escaping, leading to XSS vulnerabiliti

23 Jun 2026 · schedule it