Medium severity6.1NVD Advisory· Published Jul 7, 2020· Updated Jun 17, 2026
CVE-2019-19935
CVE-2019-19935
Description
Froala Editor before 3.2.3 allows XSS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
froala-editornpm | < 3.2.3 | 3.2.3 |
Affected products
3cpe:2.3:a:froala:froala_editor:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:froala:froala_editor:*:*:*:*:*:*:*:*range: <3.2.3
- (no CPE)
Patches
Vulnerability mechanics
References
9- github.com/froala/wysiwyg-editor/compare/v3.0.5...v3.0.6nvdPatchThird Party AdvisoryWEB
- packetstormsecurity.com/files/158300/Froala-WYSIWYG-HTML-Editor-3.1.1-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- blog.compass-security.com/2020/07/yet-another-froala-0-day-xss/nvdExploitThird Party Advisory
- compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2020-004_DOM_XSS_in_Froala_WYSIWYG_HTML_Editor.txtnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-h236-g5gh-vq6cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-19935ghsaADVISORY
- snyk.io/vuln/npm:froala-editornvdThird Party AdvisoryWEB
- blog.compass-security.com/2020/07/yet-another-froala-0-day-xssghsaWEB
- froala.com/wysiwyg-editor/changelog/ghsaWEB
News mentions
0No linked articles in our index yet.