Description Editor.md 1.5.0 has DOM-based XSS via vectors involving the 'Remediation References https://github.com/pandao/editor.md/issues/662 Related Vulnerabilities CVE-2021-4329 Vulnerability in maven package org.webjars.npm:json-logic-js CVE-2016-10735 Vulnerability in maven package li.rudin.mavenjs:bootstrap CVE-2020-28442 Vulnerability in maven package org.webjars.npm:js-data CVE-2020-5245 Vulnerability in maven package io.dropwizard:dropwizard-validation CVE-2020-36048 Vulnerability in maven package org.webjars.npm:engine.io Severity High Classification CWE-79 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Exploit Third Party Advisory