๐Ÿ” CVE Alert

CVE-2026-65841

UNKNOWN 0.0

Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This issue is fixed in version 4.13.6.

CWE CWE-80
Vendor xdan
Product jodit
Published Jul 31, 2026
Last Updated Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for xdan jodit

Be the first to know when new unknown vulnerabilities affecting xdan jodit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

xdan / jodit
< 4.13.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/xdan/jodit/security/advisories/GHSA-45qg-252v-3f7p github.com: https://github.com/xdan/jodit/commit/49a31f451f6b686f5610022a1d4406ee85138dc5 github.com: https://github.com/xdan/jodit/releases/tag/4.13.6