MEDIUM6.1
GHSA-549p-5c7f-c5p4
Froala WYSIWYG editor allows cross-site scripting (XSS)
Details
Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/froala-editor
Introduced in:
0No fixed version published yet for froala-editor (npm). Pin to a known-safe version or switch to an alternative.
Packagist/froala/wysiwyg-editor
Introduced in:
0No fixed version published yet for froala/wysiwyg-editor (composer). Pin to a known-safe version or switch to an alternative.