Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-45qg-252v-3f7p | Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization |
Fri, 31 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xdan
Xdan jodit |
|
| Vendors & Products |
Xdan
Xdan jodit |
Fri, 31 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This issue is fixed in version 4.13.6. | |
| Title | Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-31T20:05:10.590Z
Reserved: 2026-07-22T23:16:47.753Z
Link: CVE-2026-65841
Updated: 2026-07-31T20:04:40.097Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T20:30:17Z
Github GHSA