Description
All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.15.0
References
Related Issues
- Cross-site Scripting in React Draft Wysiwyg - CVE-2021-31712
- Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - vega-expression - CVE-2025-59840
- Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - CVE-2025-59840
- Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - vega-interpreter - CVE-2025-59840
You might also like:
- Tags:
- npm
- react-draft-wysiwyg
Anything's wrong? Let us know Last updated on April 04, 2025


