Количество 2
Количество 2
CVE-2025-3191
10 месяцев назад
All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.
CVSS3: 6.1
EPSS: Низкий
GHSA-fq5x-7292-2p5r
10 месяцев назад
React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button
CVSS3: 6.1
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-3191 All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag. | CVSS3: 6.1 | 0% Низкий | 10 месяцев назад | |
GHSA-fq5x-7292-2p5r React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button | CVSS3: 6.1 | 0% Низкий | 10 месяцев назад |
Уязвимостей на страницу
20