{"id":"CVE-2023-41592","details":"Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.","aliases":["GHSA-hvpq-7vcc-5hj5"],"modified":"2026-08-12T03:51:33.689932561Z","published":"2023-09-14T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/41xxx/CVE-2023-41592.json"},"references":[{"type":"WEB","url":"https://hacker.soarescorp.com/cve/2023-41592/"},{"type":"WEB","url":"https://owasp.org/Top10/A03_2021-Injection/"},{"type":"WEB","url":"https://owasp.org/www-project-top-ten/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/41xxx/CVE-2023-41592.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41592"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/froala/wysiwyg-editor","events":[{"introduced":"7de2dc8d0ee9404d8df158a104fd0a128d6063aa"},{"last_affected":"b724a92f9441f28558b9344e77f71bb1be36079f"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:froala:froala_editor:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.0.1"},{"last_affected":"4.1.1"}]}}],"versions":["v4.1.1","v4.1.0","v4.0.19","v4.0.18","v4.0.17","v4.0.16","v4.0.15","v4.0.14","v4.0.13","v4.0.12","v4.0.11","v4.0.10","v4.0.9","v4.0.8","v4.0.7","v4.0.6","v4.0.5","v4.0.4","v4.0.3","v4.0.2","v4.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-41592.json"}}],"schema_version":"1.9.0"}