CVE-2024-37063: Ydataai Ydata-Profiling
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser.
Affected products
- Ydataai Ydata-Profiling: from 3.7.0; up to and including 3.7.0
Published 2024-06-04. Last modified 2026-06-17.