← Back

CVE-2026-25581

nvd nist
Published: Feb 6, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: security-advisories@github.com (Secondary)

Description

SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control configuration options passed to sceditor.create(), like emoticons, charset, etc. then it's possible for them to trigger an XSS attack due to lack of sanitisation of configuration options. This vulnerability is fixed in 3.2.1.

Affected (1)

Products: Sceditor: Sceditor
1 product
Sceditor
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.2.1

References (2)

Timeline

No history available yet.