Medium severity6.1NVD Advisory· Published Oct 26, 2021· Updated Jun 17, 2026
CVE-2020-22864
CVE-2020-22864
Description
A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor 3.1.0 allows attackers to execute arbitrary web scripts or HTML.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
froala-editornpm | < 4.0.11 | 4.0.11 |
Affected products
3- cpe:2.3:a:froala:froala_editor:3.1.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- github.com/froala/wysiwyg-editor/issues/3880nvdExploitIssue TrackingThird Party AdvisoryWEB
- www.youtube.com/watchnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-97x5-cc53-cv4vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-22864ghsaADVISORY
- github.com/418sec/wysiwyg-editor/pull/1ghsaWEB
- github.com/froala/wysiwyg-editor/pull/3911ghsaWEB
- github.com/froala/wysiwyg-editor/releases/tag/v4.0.11ghsaWEB
News mentions
0No linked articles in our index yet.