Medium severity6.1NVD Advisory· Published Apr 5, 2021· Updated Jul 9, 2026
CVE-2021-30109
CVE-2021-30109
Description
Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creation module.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
froala-editornpm | <= 3.2.6 | — |
Affected products
3- cpe:2.3:a:froala:froala_editor:3.2.6:*:*:*:*:*:*:*
- Froala Editor/Froala Editordescription
Patches
Vulnerability mechanics
References
4- github.com/Hackdwerg/CVE-2021-30109/blob/main/README.mdnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-cq6w-w5rj-p9x8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-30109ghsaADVISORY
- froala.comghsaWEB
News mentions
0No linked articles in our index yet.