VDB
Sign up
MEDIUM6.1

GHSA-549p-5c7f-c5p4

Froala WYSIWYG editor allows cross-site scripting (XSS)

Details

Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/froala-editor
Introduced in: 0

No fixed version published yet for froala-editor (npm). Pin to a known-safe version or switch to an alternative.

Packagist/froala/wysiwyg-editor
Introduced in: 0

No fixed version published yet for froala/wysiwyg-editor (composer). Pin to a known-safe version or switch to an alternative.

References