Vulnerabilities/

Quill is vulnerable to XSS via HTML export feature

Severity:
Low

Description

A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS).

This issue affects Quill: 2.0.3.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
quill
Anything's wrong? Let us know Last updated on January 16, 2026