Description
All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.15.0
References
Could your website be exposed too?
SmartScanner can check your website for React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-site Scripting in React Draft Wysiwyg - CVE-2021-31712
- Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - vega-expression - CVE-2025-59840
- Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - CVE-2025-59840
- Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - vega-interpreter - CVE-2025-59840
You might also like:
See something that needs correcting? Let us knowUpdated April 04, 2025


