THREAT OPS › Threat News › [NVD] CVE-2026-58263 (HIGH 7.2) — Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in clean-html sanitizer can be bypassed by a MathML/<style> carrier that hides a dangerous element from the sanitizer's element walk, so a no-interaction event ha
[NVD] CVE-2026-58263 (HIGH 7.2) — Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in clean-html sanitizer can be bypassed by a MathML/<style> carrier that hides a dangerous element from the sanitizer's element walk, so a no-interaction event ha
CVE-2026-58263 CVSS: 7.2 HIGH Published: 2026-07-01T21:17:04.340
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in clean-html sanitizer can be bypassed by a MathML/<style> carrier that hides a dangerous element from the sanitizer's element walk, so a no-interaction event handler survives into the editor value, potentially caus
Indicators of compromise
- CVE-2026-58263cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-58263