[Follow-up] Add experimental WebUI for short messages with session-based login #942
Sourcery AI / Sourcery review
failed
Mar 15, 2026 in 43s
❌ Found 38 blocking security issues
Sourcery found 38 blocking security issues:
XMOJ.user.js:685- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:685- User controlled data in aToastTime.innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:695- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:695- User controlled data in aToastBody.innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:743- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:743- User controlled data in aToastTime.innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:1622-1624- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:1622-1624- User controlled data in aStyle.innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:1917- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:1917- User controlled data in aUpdateDataCardListItem.innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:2269- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:2269- User controlled data in adocument.getElementsByTagName("h2")[0].innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:2322- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:2322- User controlled data in aproblemSwitcher.innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:2354- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:2354- User controlled data in adocument.querySelector('.mt-3 > center:nth-child(1)').innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:2665- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:2665- User controlled data in aRows[i].cells[2].innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:2723- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:2723- User controlled data in aCurrentRow.cells[2].innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:2725- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:2725- User controlled data in aCurrentRow.cells[2].innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:3454- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:3454- User controlled data in aUpdateDataCardListItem.innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:3745- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:3745- User controlled data in aUserInfoElement.innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:3746- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:3746- User controlled data in aUserInfoElement.innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:4370- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:4370- User controlled data in aTemp[i].children[1].innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:4894- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:4894- User controlled data in aTitleLink.innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:5238- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:5238- User controlled data in aPostTitle.innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:5243- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:5243- User controlled data in aPostBoard.innerHTMLis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:5393- User controlled data in methods likeinnerHTML,outerHTMLordocument.writeis an anti-pattern that can lead to XSS vulnerabilitiesXMOJ.user.js:5393- User controlled data in aReplyContentElement.innerHTMLis an anti-pattern that can lead to XSS vulnerabilities
Loading