CVE-2026-1513: Naver Billboard.js
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.
Affected products
- Naver Billboard.js: before 3.18.0 (fixed in 3.18.0)
Published 2026-01-28. Last modified 2026-06-17.