GHSA-9hfw-cvf4-5x25MediumCVSS 5.4

wangEditor was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload function

Published
May 31, 2024
Last Modified
June 11, 2026

🔗 CVE IDs covered (1)

📋 Description

There is a cross-site scripting (XSS) issue in wangEditor via the image upload function in version 4.7.11. This issue has been fixed in version 4.7.12.

🎯 Affected products1

  • npm/@wangeditor/editor:<= 4.7.11

🔗 References (6)