In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9.
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:w3c:css_validator:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "2020-01-19"
}
],
"vendor_product": "w3c:css_validator"
}
]
}