Slab develops Quill, a rich-text editing and document-collaboration component widely embedded in web applications and content platforms. The vendor's vulnerability profile centers on input-handling weaknesses in the editor, particularly cross-site scripting risks arising from the challenge of sanitizing and neutralizing user-supplied content in real-time collaborative editing contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Slab over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3163MEDIUM A vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute of an IMG eleme | Apr 12, 2021 | 6.1 | 22 | NO | NO |
CVE-2025-15056MEDIUM A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS).
This issue affects Quill: 2.0.3. | Jan 13, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Slab.
Media articles that mention a CVE ID that affects a product developed by Slab — matched by CVE ID, not by vendor name.