mycolorway/simditor
Releases63
Frequency1 month 1 day
Last Release
Stars5.01K
An Easy and Fast WYSIWYG Editor
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| <= 2.3.21, < 2.3.22 | — | 4.3 MEDIUM | ||
Simditor through 2.3.21 allows DOM XSS via an onload attribute within a malformed SVG element. | ||||
| = 2.3.11, <= 2.3.11 | 6.1 MEDIUM | 4.3 MEDIUM | ||
Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1. | ||||