CVE-2025-3191
Severity CVSS v4.0:
LOW
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
04/04/2025
Last modified:
29/04/2026
Description
All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the tag.
Impact
Base Score 4.0
2.00
Severity 4.0
LOW
Base Score 3.x
6.10
Severity 3.x
MEDIUM



