vditor@3.8.11 vulnerabilities
♏ 易于使用的 Markdown 编辑器,为适配不同的应用场景而生
-
latest version
3.10.7
-
latest non vulnerable version
-
first published
6 years ago
-
latest version published
a month ago
-
licenses detected
- >=0
Direct Vulnerabilities
Known vulnerabilities in the vditor package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
vditor is a ♏ 易于使用的 Markdown 编辑器,为适配不同的应用场景而生 Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization. How to fix Cross-site Scripting (XSS)? Upgrade |
<3.8.13
|
vditor is a ♏ 易于使用的 Markdown 编辑器,为适配不同的应用场景而生 Affected versions of this package are vulnerable to Cross-site Scripting (XSS) when a user creates a link using the markdown syntax, the server does not URL-encode the double-quotes, so the user can escape the href attribute. How to fix Cross-site Scripting (XSS)? Upgrade |
<3.8.13
|