VYPR
Medium severity5.4OSV Advisory· Published Jul 25, 2022· Updated Jun 17, 2026

CVE-2022-21802

CVE-2022-21802

Description

The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
grapesjsnpm
>= 0

Affected products

3
  • Grapesjs/GrapesjsOSV2 versions
    v0.10.2, v0.10.4, v0.10.6, …+ 1 more
    • (no CPE)range: v0.10.2, v0.10.4, v0.10.6, …
    • cpe:2.3:a:grapesjs:grapesjs:*:*:*:*:*:node.js:*:*range: <0.19.5
  • ghsa-coords
    Range: >= 0

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.