CVE-2026-62324: Xdan Jodit

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case variants, control-byte prefixes, and embedded tabs or newlines to bypass filtering and execute attacker-controlled script when a victim clicks a stored link rendered by an application. This issue is fixed in version 4.12.31.

Affected products

  • Xdan Jodit: before 4.12.31 (fixed in 4.12.31)

Published 2026-07-31. Last modified 2026-09-09.