Description Froala Editor before 3.2.2 allows XSS via pasted content. Remediation References https://froala.com/wysiwyg-editor/changelog/ Related Vulnerabilities CVE-2023-45827 Vulnerability in npm package @clickbar/dot-diver CVE-2023-44487 Vulnerability in maven package org.apache.tomcat:tomcat-coyote CVE-2020-4075 Vulnerability in npm package electron CVE-2018-20677 Vulnerability in maven package org.webjars.npm:bootstrap CVE-2023-27490 Vulnerability in npm package next-auth Severity High Classification CWE-79 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Release Notes Vendor Advisory