Vendor
Trix
Products
2
CVEs
2
Across products
2
Status
Private
Products
2- 2 CVEs
- 0 CVEs
Recent CVEs
2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73428 | 0.00 | — | — | Jul 24, 2026 | ### Impact The Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The `HTMLParser` processed a mock attachment, a `` carrying an empty `data-trix-attachment="{}"`. The empty attachment object caused the element to… | |||
| CVE-2026-73426 | 0.00 | — | — | Mar 12, 2026 | ### Impact The Trix editor, in versions prior to 2.1.17, is vulnerable to XSS attacks when a `data-trix-serialized-attributes` attribute bypasses the DOMPurify sanitizer. An attacker could craft HTML containing a `data-trix-serialized-attributes` attribute with a malicious… |
- CVE-2026-73428Jul 24, 2026risk 0.00cvss —epss —
### Impact The Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The `HTMLParser` processed a mock attachment, a `` carrying an empty `data-trix-attachment="{}"`. The empty attachment object caused the element to…
- CVE-2026-73426Mar 12, 2026risk 0.00cvss —epss —
### Impact The Trix editor, in versions prior to 2.1.17, is vulnerable to XSS attacks when a `data-trix-serialized-attributes` attribute bypasses the DOMPurify sanitizer. An attacker could craft HTML containing a `data-trix-serialized-attributes` attribute with a malicious…