This issue affects Quill: 2.0.3.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v3m3-f69x-jf25 | Quill is vulnerable to XSS via HTML export feature |
Mon, 20 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-74 |
Fri, 10 Apr 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:slab:quill:2.0.3:*:*:*:*:node.js:*:* | |
| Metrics |
cvssV3_1
|
Tue, 13 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This issue affects Quill: 2.0.3. | |
| Title | Quill 2.0.3 - Lack of data validation in HTML export allowing XSS | |
| First Time appeared |
Slab
Slab quill |
|
| Weaknesses | CWE-74 | |
| CPEs | cpe:2.3:a:slab:quill:2.0.3:*:linux:*:*:*:*:* cpe:2.3:a:slab:quill:2.0.3:*:macos:*:*:*:*:* cpe:2.3:a:slab:quill:2.0.3:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Slab
Slab quill |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-04-20T14:10:18.123Z
Reserved: 2025-12-23T18:21:36.039Z
Link: CVE-2025-15056
Updated: 2026-01-13T21:27:50.983Z
Status : Modified
Published: 2026-01-13T21:15:49.720
Modified: 2026-04-20T16:16:40.413
Link: CVE-2025-15056
No data.
OpenCVE Enrichment
Updated: 2026-04-20T19:00:10Z
Github GHSA