Xheditor is a web-based HTML editor product with a narrow vulnerability footprint centered on cross-site scripting issues arising from improper input sanitization during page generation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xheditor over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18909MEDIUM xhEditor 1.2.2 allows XSS via JavaScript code in the SRC attribute of an IFRAME element within the editor's source-code view. | Nov 3, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xheditor.
Media articles that mention a CVE ID that affects a product developed by Xheditor — matched by CVE ID, not by vendor name.