CVE Database
/

CVE-2023-30792

Back to search

CVE-2023-30792

Published: Apr 29, 2023

Modified: Jan 30, 2025

PUBLISHED

Description

Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources.

VendorProductVersions

Meta Platforms, Inc

Lexical

affected
0.0.0 - < 0.10.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now