Xdsoft develops web-based rich text editor components, primarily through its Jodit Editor product, which is embedded in content management and web application platforms where user-generated content handling is critical. The vendor's vulnerability signal centers on cross-site scripting weaknesses arising from improper input neutralization during page generation, a class endemic to client-side editor components that process and render untrusted markup. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xdsoft over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42399MEDIUM Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component. | Sep 19, 2023 | 6.1 | 22 | NO | NO |
CVE-2022-23461MEDIUM Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed in | Sep 24, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xdsoft.
Media articles that mention a CVE ID that affects a product developed by Xdsoft — matched by CVE ID, not by vendor name.