Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-549p-5c7f-c5p4 | Froala WYSIWYG editor allows cross-site scripting (XSS) |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 08 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Froala
Froala wysiwyg Editon |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:froala:wysiwyg_editon:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Froala
Froala wysiwyg Editon |
|
| Metrics |
cvssV3_1
|
Thu, 07 Nov 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-08T16:32:11.934Z
Reserved: 2024-10-28T00:00:00.000Z
Link: CVE-2024-51434
Updated: 2024-11-08T16:32:05.452Z
Status : Deferred
Published: 2024-11-07T22:15:21.467
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-51434
No data.
OpenCVE Enrichment
No data.
Github GHSA