Summernote is a lightweight rich-text editor library embedded across web applications, with observed vulnerability exposure concentrated in cross-site scripting (XSS) weaknesses related to improper input sanitization during HTML generation. Treat this as a focused vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Summernote over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-37629MEDIUM SummerNote v0.9.1 is vulnerable to Cross Site Scripting (XSS) via the Code View Function. | Jun 12, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-29504HIGH Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the codeview parameter. | Apr 10, 2024 | 7.6 | 19 | NO | NO |
CVE-2023-42371MEDIUM Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execute arbitrary code via a crafted script to the insert link fun | Sep 18, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Summernote.
Media articles that mention a CVE ID that affects a product developed by Summernote — matched by CVE ID, not by vendor name.