Releases153
Frequency4 weeks 9 hours
Last Release
Stars47.2K
Quill is a modern WYSIWYG editor built for compatibility and extensibility

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
= 2.0.36.1 MEDIUM

A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This issue affects Quill: 2.0.3.

= 4.8.0, <= 1.3.76.1 MEDIUM4.3 MEDIUM

A vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute of an IMG element) in a text field. Note: Researchers have claimed that this issue is not within the product itself, but is intended behavior in a web browser