Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36600
HistoryAug 04, 2022 - 4:21 a.m.

Cross-site Scripting (XSS)

2022-08-0404:21:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.001 Low

EPSS

Percentile

39.4%

@ckeditor/ckeditor5-markdown-gfm is vulnerable to cross-site scripting. An attacker can inject and execute a malicious javascript if the library uses an unsafe markup configuration inside the editor, initializes the editor on an element that uses an element other than `` as a base, or destroys the editor instance.

0.001 Low

EPSS

Percentile

39.4%