Medium severity6.1NVD Advisory· Published Jan 11, 2021· Updated Jun 17, 2026
CVE-2020-23849
CVE-2020-23849
Description
Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jsoneditornpm | < 9.0.2 | 9.0.2 |
Affected products
3- cpe:2.3:a:jsoneditoronline:jsoneditor:*:*:*:*:*:*:*:*Range: >=8.6.6,<9.0.2
- jsoneditor/jsoneditordescription
Patches
Vulnerability mechanics
References
3- github.com/josdejong/jsoneditor/issues/1029nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-q854-j362-cfq9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-23849ghsaADVISORY
News mentions
0No linked articles in our index yet.