Description
The Trix editor, in versions prior to 2.1.16, is vulnerable to XSS attacks through attachment payloads.
Recommendation
Update the trix package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.1.16
- Patched version(s): 2.1.16
References
Could your website be exposed too?
SmartScanner can check your website for Trix has a stored XSS vulnerability through its attachment attribute and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Trix has a Stored XSS vulnerability through serialized attributes - CVE-2026-73426
- devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted - Vulnerability
- NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability - CVE-2026-30048
- Trix: Stored XSS via HTMLParser attribute injection on paste - CVE-2026-73428
You might also like:
See something that needs correcting? Let us knowUpdated January 08, 2026


