VYPR

jodit

by Xdan

Source repositories

CVEs (5)

  • CVE-2026-58263HigJul 1, 2026
    risk 0.40cvss 7.2epss 0.00

    Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in clean-html sanitizer can be bypassed by a MathML/ carrier that hides a dangerous element from the sanitizer's element walk, so a no-interaction event…

  • CVE-2026-55886MedJul 1, 2026
    risk 0.34cvss epss 0.00

    Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to 4.12.26 are vulnerable to Prototype Pollution through Jodit.modules.Helpers.set(chain, value, obj), which walks the dot-separated chain, creating and following…

  • CVE-2026-54756MedJul 1, 2026
    risk 0.34cvss epss 0.00

    Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior to 4.12.18, Jodit.configure(options) — and the internal ConfigMerge / ConfigProto helpers — merged user-supplied options into the editor configuration…

  • CVE-2026-62324MedJul 31, 2026
    risk 0.28cvss 5.4epss 0.00

    Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case variants, control-byte prefixes, and…

  • CVE-2026-65841MedJul 31, 2026
    risk 0.27cvss epss 0.00

    Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and…