CVE-2025-15056

Severity CVSS v4.0:
MEDIUM
Type:
CWE-74 Injection
Publication date:
13/01/2026
Last modified:
10/04/2026

Description

A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS).<br /> <br /> This issue affects Quill: 2.0.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:slab:quill:2.0.3:*:*:*:*:node.js:*:*