suneditor is vulnerable to Cross-Site Scripting (XSS)
100
Critical Risk
SunEditor's HTML sanitization does not fully strip executable event-handler attributes from crafted namespaced or custom tags such as <a:b>. An attacker can submit editor content containing these tags with attributes like onclick or JavaScript URI schemes, and the malicious attributes survive sanitization and execute when the rendered element is interacted with. Depending on how the editor output is stored and displayed, this enables stored or reflected cross-site scripting in the victim's browser context. The fix sanitizes code-view input before parsing and tightens the disallowed-tag matching to cover additional script-adjacent tags and namespaced selectors.
You are affected if you are using a version that falls within the vulnerable range.
suneditor is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 2.47.10.
Upgrade the suneditor library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant