slippers
A UI component framework for Django. Built on top of Django Template Language.
Activity
- Latest release
- 1mo ago
- Total releases
- 20
- Cadence
- ~5 days
- Last 12 months
- 3
Reach
- Stars
- 575
Details
- License
- MIT
- First release
- Jul 11, 2021
| Version | Released | |
|---|---|---|
0.7.1
patch
| ||
0.7.0
minor
| ||
0.6.3
patch
| ||
0.6.2
patch
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.1
patch
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.1a0
pre
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.0a0
pre
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.0a0
pre
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.3.2
patch
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.4
patch
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.3
patch
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.2
patch
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.1
patch
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
CVE-2026-34231
PYSEC-2026-2279
GHSA-w7rv-gfp4-j9j3
Mar 31, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.0a0
+ 5 more Show less
0.6.0
0.6.0a0
0.6.1
0.6.1a0
0.6.2
Fixed in
0.6.3
References Updated Jul 13, 2026 · Source: OSV.dev |