React Draft Wysiwyg Project develops a JavaScript-based rich-text editing library for React applications, a component commonly integrated into web platforms that handle user-generated content. The durable signal in its vulnerability profile centers on cross-site scripting risks inherent to WYSIWYG editors, where improper input neutralization during content rendering creates a persistent class of exposure. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by React Draft Wysiwyg Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31712MEDIUM react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decorator in decorators/Link/index.js when a draft is shared acros | Apr 24, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by React Draft Wysiwyg Project.
Media articles that mention a CVE ID that affects a product developed by React Draft Wysiwyg Project — matched by CVE ID, not by vendor name.