Description
A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS).
This issue affects Quill: 2.0.3.
Recommendation
No fix is available yet. Followings are affected versions:
- = 2.0.3
References
Could your website be exposed too?
SmartScanner can check your website for Quill is vulnerable to XSS via HTML export feature and gives you actionable findings to investigate.
Start a free scanRelated Issues
- jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin - CVE-2025-9910
- Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data - CVE-2025-47204
- Fiora chat user avatar is vulnerable to XSS via SVG files - CVE-2025-56514
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
You might also like:
See something that needs correcting? Let us knowUpdated April 10, 2026


