Vulnerabilities/

Trix vulnerable to Cross-site Scripting on copy & paste

Severity:
Low

Description

The Trix editor, in versions prior to 2.1.15, is vulnerable to XSS attacks when pasting malicious code.

Recommendation

Update the trix package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
trix
Anything's wrong? Let us know Last updated on May 08, 2025

This issue is available in SmartScanner Professional

See Pricing