VYPR
Vendor

Trix

Products
2
CVEs
2
Across products
2
Status
Private

Products

2

Recent CVEs

2
  • CVE-2026-73428Jul 24, 2026
    risk 0.00cvss epss

    ### Impact The Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The `HTMLParser` processed a mock attachment, a `` carrying an empty `data-trix-attachment="{}"`. The empty attachment object caused the element to…

  • CVE-2026-73426Mar 12, 2026
    risk 0.00cvss epss

    ### Impact The Trix editor, in versions prior to 2.1.17, is vulnerable to XSS attacks when a `data-trix-serialized-attributes` attribute bypasses the DOMPurify sanitizer. An attacker could craft HTML containing a `data-trix-serialized-attributes` attribute with a malicious…