Udecode / Plate
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-88976 | @platejs/core HTML deserialization can trigger browser behavior during parsing | MEDIUM | 6.1 | Sep 16, 2026 |
| CVE-2026-65842 | Plate: SSRF with response disclosure in DOCX image embedding | HIGH | 8.2 | Aug 20, 2026 |
| CVE-2026-55596 | Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript | HIGH | 8.7 | Jul 8, 2026 |
| CVE-2024-47061 | Arbitrary DOM attributes in element.attributes and leaf.attributes in Platejs | HIGH | 8.7 | Sep 20, 2024 |
| CVE-2024-40631 | Cross-site Scripting (XSS) in media embed element when using custom URL parsers in plate media | HIGH | 8.4 | Jul 15, 2024 |
| CVE-2023-34245 | Cross site scripting (XSS) in @udecode/plate-link | HIGH | 8.1 | Jun 9, 2023 |
Showing 1 to 6 of 6 CVEs