CVE-2026-25581
Last modified
CVE-2026-25581 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control configuration options passed to sceditor.create(), like emoticons, charset, etc. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control configuration options passed to sceditor.create(), like emoticons, charset, etc. then it's possible for them to trigger an XSS attack due to lack of sanitisation of configuration options. This vulnerability is fixed in 3.2.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sceditor | Sceditor | < 3.2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-25581?
How severe is CVE-2026-25581?
How do I fix CVE-2026-25581?
Are you affected by CVE-2026-25581?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
