You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The next generation Javascript WYSIWYG HTML rich text editor made by devs for devs. High performance and modern design make it easy to use for developers and loved by users.
The next generation Javascript WYSIWYG HTML rich text editor made by devs for devs. High performance and modern design make it easy to use for developers and loved by users.
The next generation Javascript WYSIWYG HTML rich text editor made by devs for devs. High performance and modern design make it easy to use for developers and loved by users.
Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creation module.
The next generation Javascript WYSIWYG HTML rich text editor made by devs for devs. High performance and modern design make it easy to use for developers and loved by users.
The next generation Javascript WYSIWYG HTML rich text editor made by devs for devs. High performance and modern design make it easy to use for developers and loved by users.
A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor 3.1.0 allows attackers to execute arbitrary web scripts or HTML.
mend-for-jackfan.us.kgbot
changed the title
froala-editor-3.2.1.tgz: 3 vulnerabilities (highest severity is: 6.1) unreachable
froala-editor-3.2.1.tgz: 4 vulnerabilities (highest severity is: 6.1)
Nov 8, 2024
mend-for-jackfan.us.kgbot
changed the title
froala-editor-3.2.1.tgz: 4 vulnerabilities (highest severity is: 6.1)
froala-editor-3.2.1.tgz: 4 vulnerabilities (highest severity is: 6.1) unreachable
Jan 22, 2025
The next generation Javascript WYSIWYG HTML rich text editor made by devs for devs. High performance and modern design make it easy to use for developers and loved by users.
Library home page: https://registry.npmjs.org/froala-editor/-/froala-editor-3.2.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/froala-editor/package.json
Found in HEAD commit: 0a860faab62f61e45dc9d2161fe675865f86263b
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - froala-editor-3.2.1.tgz
The next generation Javascript WYSIWYG HTML rich text editor made by devs for devs. High performance and modern design make it easy to use for developers and loved by users.
Library home page: https://registry.npmjs.org/froala-editor/-/froala-editor-3.2.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/froala-editor/package.json
Dependency Hierarchy:
Found in HEAD commit: 0a860faab62f61e45dc9d2161fe675865f86263b
Found in base branch: main
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.
Publish Date: 2024-11-07
URL: CVE-2024-51434
CVSS 3 Score Details (6.1)
Base Score Metrics:
Vulnerable Library - froala-editor-3.2.1.tgz
The next generation Javascript WYSIWYG HTML rich text editor made by devs for devs. High performance and modern design make it easy to use for developers and loved by users.
Library home page: https://registry.npmjs.org/froala-editor/-/froala-editor-3.2.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/froala-editor/package.json
Dependency Hierarchy:
Found in HEAD commit: 0a860faab62f61e45dc9d2161fe675865f86263b
Found in base branch: main
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creation module.
Publish Date: 2021-04-05
URL: CVE-2021-30109
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2021-30109
Release Date: 2021-04-05
Fix Resolution: 3.2.6-1
⛑️ Automatic Remediation will be attempted for this issue.
Vulnerable Library - froala-editor-3.2.1.tgz
The next generation Javascript WYSIWYG HTML rich text editor made by devs for devs. High performance and modern design make it easy to use for developers and loved by users.
Library home page: https://registry.npmjs.org/froala-editor/-/froala-editor-3.2.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/froala-editor/package.json
Dependency Hierarchy:
Found in HEAD commit: 0a860faab62f61e45dc9d2161fe675865f86263b
Found in base branch: main
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
Froala Editor before 3.2.2 allows XSS via pasted content.
Publish Date: 2020-10-02
URL: CVE-2020-26523
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://froala.com/wysiwyg-editor/changelog/#3.2.2
Release Date: 2020-10-02
Fix Resolution: 3.2.2
⛑️ Automatic Remediation will be attempted for this issue.
Vulnerable Library - froala-editor-3.2.1.tgz
The next generation Javascript WYSIWYG HTML rich text editor made by devs for devs. High performance and modern design make it easy to use for developers and loved by users.
Library home page: https://registry.npmjs.org/froala-editor/-/froala-editor-3.2.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/froala-editor/package.json
Dependency Hierarchy:
Found in HEAD commit: 0a860faab62f61e45dc9d2161fe675865f86263b
Found in base branch: main
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor 3.1.0 allows attackers to execute arbitrary web scripts or HTML.
Publish Date: 2021-10-26
URL: CVE-2020-22864
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2020-22864
Release Date: 2021-10-26
Fix Resolution: 4.0.7
⛑️ Automatic Remediation will be attempted for this issue.
⛑️Automatic Remediation will be attempted for this issue.
The text was updated successfully, but these errors were encountered: