Medium severity5.4NVD Advisory· Published Jul 16, 2021· Updated Jun 17, 2026
CVE-2021-28114
CVE-2021-28114
Description
Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
froala/wysiwyg-editorPackagist | < 3.2.7 | 3.2.7 |
Affected products
3Patches
Vulnerability mechanics
References
6- froala.com/wysiwyg-editor/nvdVendor Advisory
- github.com/advisories/GHSA-rr6v-h7m8-wc9fghsaADVISORY
- labs.bishopfox.com/advisoriesnvdThird Party Advisory
- labs.bishopfox.com/advisories/froala-editor-v3.2.6nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-28114ghsaADVISORY
- froala.com/wysiwyg-editorghsaWEB
News mentions
0No linked articles in our index yet.