jodit vulnerabilities
CVEs whose affected-version data names the jodit package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-62324Medium· 5.4Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case…
CVE-2026-54756MediumJodit has prototype pollution via Jodit.configure() / ConfigMerge
Jodit has prototype pollution via Jodit.configure() / ConfigMerge
CVE-2026-58263High· 7.2Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
CVE-2026-65841MediumJodit Editor is a WYSIWYG editor with a built-in file browser & image editor
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SV…
CVE-2026-55886Mediumjodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()
jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()