devextreme-quill is vulnerable to Improper Input Validation
77
High Risk
Affected versions of this package are vulnerable due to insufficient validation of user-uploaded SVG files. Malicious SVGs can include scripts, event handlers, or external references that execute when rendered, leading to cross-site scripting (XSS), data theft, or phishing. Attackers may also craft SVGs to cause excessive resource consumption and denial-of-service (DoS).
You are affected if you are using a version that falls within the vulnerable range.
devextreme-quill is vulnerable to Improper Input Validation in versions 1.7.0 - 1.7.5 and 0.9.0 - 1.6.5.
Upgrade the devextreme-quill library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant