platejs has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 8.4 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.4
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
platejs vulnerabilities
CVEs affecting platejs, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-55596High· 8.7Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
▾ Twilightplatejs · @platejs/mediaEPSS 0.43%via GHSA
CVE-2026-65842High· 8.2Plate is a rich-text editor with AI and shadcn/ui
Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can…
▾ Twilightplatejs · @platejs/docx-ioEPSS 0.30%via NVD