jodit has 5 CVEs on record. 4 were published in the last 90 days. The busiest recent month was July 2026 with 4. The median CVSS is 6.3 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 4 prev 1
Weakness classes
Products
- jodit 5
Worst active — by depth score
CVE-2026-58263High· 7.2Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier40CVE-2026-62324Medium· 5.4Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor30CVE-2026-65841MediumJodit Editor is a WYSIWYG editor with a built-in file browser & image editor28CVE-2026-54756MediumJodit has prototype pollution via Jodit.configure() / ConfigMerge28CVE-2026-55886Mediumjodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()28
jodit vulnerabilities
CVEs affecting jodit, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-62324Medium· 5.4Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case…
CVE-2026-54756MediumJodit has prototype pollution via Jodit.configure() / ConfigMerge
Jodit has prototype pollution via Jodit.configure() / ConfigMerge
CVE-2026-58263High· 7.2Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
CVE-2026-65841MediumJodit Editor is a WYSIWYG editor with a built-in file browser & image editor
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SV…
CVE-2026-55886Mediumjodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()
jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()