CVE-2025-3191 Information
Apr 05, 2025
cve
Description
All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the
Reference
https://gist.github.com/th4s1s/175ae4b2632096059b42377dd6c49d47 https://gist.github.com/th4s1s/175ae4b2632096059b42377dd6c49d47 https://security.snyk.io/vuln/SNYK-JS-REACTDRAFTWYSIWYG-8515884
Share on: