suneditor is vulnerable to Improper Input Validation
62
Medium Risk
Affected versions of this package are vulnerable to a sanitizer/filter bypass in SunEditor that can lead to stored or reflected cross-site scripting (XSS), allowing untrusted editor content to execute arbitrary JavaScript in the rendered output. An attacker could exploit this by crafting a malicious payload that survives sanitization and is later viewed by another user, potentially enabling session theft, unauthorized actions, or delivery of further client-side attacks.
You are affected if you are using a version that falls within the vulnerable range.
suneditor is vulnerable to Improper Input Validation in versions 0.0.1 - 2.47.9.
Upgrade the suneditor library to the legacy patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant