CVE-2020-28487: Visjs Vis-Timeline

Medium severity, CVSS 6.8. EPSS: 1.4% chance of exploitation in the next 30 days.

This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.

Affected products

  • Visjs Vis-Timeline: before 7.4.4 (fixed in 7.4.4)

Published 2021-01-22. Last modified 2026-06-17.