High severity7.6NVD Advisory· Published Apr 10, 2024· Updated Jun 17, 2026
CVE-2024-29504
CVE-2024-29504
Description
Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the codeview parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
summernotenpm | <= 0.8.18 | — |
Affected products
3- Summernote/Summernotedescription
Patches
Vulnerability mechanics
References
4- github.com/summernote/summernote/pull/3782nvdExploitIssue TrackingWEB
- gist.github.com/phoenix118go/a9192281efcfa518daa709ab7638712bnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-4wh3-3wf2-39m9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-29504ghsaADVISORY
News mentions
0No linked articles in our index yet.