Количество 2
Количество 2
CVE-2026-65841
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This issue is fixed in version 4.13.6.
GHSA-45qg-252v-3f7p
Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-65841 Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This issue is fixed in version 4.13.6. | 0% Низкий | 7 дней назад | ||
GHSA-45qg-252v-3f7p Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization | 0% Низкий | 7 дней назад |
Уязвимостей на страницу