A rich text editor for everyday writing
92%
Total Score
95
97
89
100
0
| Title | Versions | Severity |
|---|---|---|
CVE-2026-73428 trix is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.1.18. | 0.0.0 - 2.1.18 | Medium |
CVE-2026-73427 trix is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.1.18. | 0.0.0 - 2.1.18 | Low |
AIKIDO-2025-10299 trix is vulnerable to Cross-site Scripting (XSS) in versions 0.9.0 - 2.1.14. | 0.9.0 - 2.1.14 | Medium |
CVE-2025-21610 trix is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.1.12. | 0.0.0 - 2.1.12 | Medium |
CVE-2024-53847 trix is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.0.0 - 2.1.9 and 1.0.0 - 1.3.3. | 1.0.0 - 1.3.32.0.0 - 2.1.9 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
dompurify Version ^3.2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant