VendorsBaiduueditorall versions
Vulnerabilities

Baidu UEditor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2017-14744
UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element.
Published 2017-09-26 · Modified
6.1EPSS 0.006
CVE-2024-7342
Baidu UEditor unrestricted upload
Published 2024-08-01 · Analyzed
6.1EPSS 0.005
CVE-2024-7343
Baidu UEditor cross site scripting
Published 2024-08-01 · Analyzed
6.1EPSS 0.005
CVE-2021-37271
Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information.
Published 2021-09-28 · Modified
5.4EPSS 0.006