Udecode

Plate

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 16:40:24
  • Zuletzt bearbeitet 20.08.2026 17:19:23

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can make request...

  • EPSS 0.24%
  • Veröffentlicht 08.07.2026 20:27:58
  • Zuletzt bearbeitet 10.07.2026 19:06:45

Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized provider or sourceUrl metadata in useMediaState and skips parseMediaUrl protocol validation, allowing a crafted Plate document to ...

  • EPSS 0.52%
  • Veröffentlicht 20.09.2024 19:15:16
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature of Plate is the ability to add custom DOM attributes to any element or leaf using the `attribute...

  • EPSS 0.5%
  • Veröffentlicht 15.07.2024 19:15:03
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlParsers` to the `useMediaState` hook may be vulnerable to XSS if a custom parser allows `javascript:`, `data:` or `vbscript:` URLs to ...

  • EPSS 0.45%
  • Veröffentlicht 09.06.2023 18:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:51

@udecode/plate-link is the link handler for the udecode/plate rich-text editor plugin system for Slate & React. Affected versions of the link plugin and link UI component do not sanitize URLs to prevent use of the `javascript:` scheme. As a result, l...