{"api_version":"1","generated_at":"2026-07-23T11:52:17+00:00","cve":"CVE-2022-23461","urls":{"html":"https://cve.report/CVE-2022-23461","api":"https://cve.report/api/cve/CVE-2022-23461.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-23461","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-23461"},"summary":{"title":"CVE-2022-23461","description":"Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2022-09-24 03:15:00","updated_at":"2022-09-27 19:25:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://securitylab.github.com/advisories/GHSL-2022-030_xdan_jodit/","name":"N/A","refsource":"CONFIRM","tags":[],"title":"GHSL-2022-030: Cross-Site Scripting (XSS) in Jodit Editor 3 - CVE-2022-23461 | GitHub Security Lab","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-23461","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23461","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"23461","vulnerable":"1","versionEndIncluding":"3.20.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xdsoft","cpe5":"jodit_editor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2022-23461","STATE":"PUBLIC","TITLE":"Cross-Site Scripting (XSS) in Jodit Editor"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Jodit Editor","version":{"version_data":[{"version_affected":"<=","version_name":"3.20.4","version_value":"3.20.4"}]}}]},"vendor_name":"xdan"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79 Cross-site Scripting (XSS)"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://securitylab.github.com/advisories/GHSL-2022-030_xdan_jodit/","name":"https://securitylab.github.com/advisories/GHSL-2022-030_xdan_jodit/"}]},"source":{"advisory":"GHSL-2022-030","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2022-09-24 03:15:00","lastModifiedDate":"2022-09-27 19:25:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:xdsoft:jodit_editor:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.0","versionEndIncluding":"3.20.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"23461","Ordinal":"226404","Title":"CVE-2022-23461","CVE":"CVE-2022-23461","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"23461","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}