VYPR

Trix editor

by Trix

CVEs (2)

  • CVE-2026-73428Jul 24, 2026
    risk 0.00cvss epss

    ### Impact The Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The `HTMLParser` processed a mock attachment, a `` carrying an empty `data-trix-attachment="{}"`. The empty attachment object caused the element to…

  • CVE-2026-73426Mar 12, 2026
    risk 0.00cvss epss

    ### Impact The Trix editor, in versions prior to 2.1.17, is vulnerable to XSS attacks when a `data-trix-serialized-attributes` attribute bypasses the DOMPurify sanitizer. An attacker could craft HTML containing a `data-trix-serialized-attributes` attribute with a malicious…