GHSA-w3wh-g4m9-783p
CRITICALCVE-2025-53835The XHTML syntax depended on the xdom+xml/current syntax which allows the creation of raw blocks that permit the insertion of arbitrary HTML content including JavaScript. This allows XSS attacks for users who can edit a document like their user profile (enabled by default). The attack works by setting the document's syntax to xdom+xml/current and then inserting content like
- Affected
- >= 5.4.5, < 14.10
- Fixed in
- 14.10
- Weakness
- CWE-79
- Published
- 2025-07-14
- Source
- github