CVE-2025-8082

MEDIUM

Vuetify 2.0.0-3.0.0 - Stored Cross-Site Scripting via VDatePicker Title Date Format

Title source: llm
STIX 2.1

Description

Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inserted into the page. This can lead to a Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss  attack. The vulnerability occurs because the 'title-date-format' property of the 'VDatePicker' can accept a user created function and assign its output to the 'innerHTML' property of the title element without sanitization. This issue affects Vuetify versions greater than or equal to 2.0.0 and less than 3.0.0. Note: Version 2.x of Vuetify is End-of-Life and will not receive any updates to address this issue. For more information see here https://v2.vuetifyjs.com/en/about/eol/ .

References (2)

Core 2
Core References
Various Sources technical-description exploit
https://codepen.io/herodevs/pen/dPYGPyR/775285c0fd5a08038d4c85398815d644

Scores

CVSS v3 6.3
EPSS 0.0003
EPSS Percentile 7.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
N/A/Vuetify >=2.0.0 <3.0.0
npm/vuetify 2.0.0 - 3.0.0npm
Published Dec 12, 2025
Tracked Since Feb 18, 2026