slab/quill
Releases153
Frequency4 weeks 9 hours
Last Release
Stars47.2K
Quill is a modern WYSIWYG editor built for compatibility and extensibility
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| = 2.0.3 | 6.1 MEDIUM | — | ||
A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This issue affects Quill: 2.0.3. | ||||
| = 4.8.0, <= 1.3.7 | 6.1 MEDIUM | 4.3 MEDIUM | ||
A vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute of an IMG element) in a text field. Note: Researchers have claimed that this issue is not within the product itself, but is intended behavior in a web browser | ||||