Vulnerability record · CVE-2021-28114 · published 16 July 2021
CVE-2021-28114: Froala WYSIWYG Editor namespace confusion leads to XSS
Froala · Froala Editor
Froala WYSIWYG Editor 3.2.6-1 is affected by cross-site scripting caused by namespace confusion during parsing. The flaw allows script injection through crafted content, which matters because the editor is commonly embedded in web applications where rendered content is trusted.
Description
Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (5.4) with required privileges and user interaction, though the high EPSS percentile warrants attention.
What it is
Froala WYSIWYG Editor 3.2.6-1 is affected by cross-site scripting caused by namespace confusion during parsing. The flaw allows script injection through crafted content, which matters because the editor is commonly embedded in web applications where rendered content is trusted.
Impact
An attacker can execute script in the context of a victim's browser session, potentially stealing session data or performing actions as the victim. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through the editor's parsing of crafted content; the vector requires low privileges (PR:L) and user interaction (UI:R), so an authenticated user must interact with the malicious content.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high at 0.52037 (99th percentile), suggesting elevated likelihood of exploitation activity, but the references are only vendor and third-party advisories with no public exploit tag.
What to do
- Upgrade Froala WYSIWYG Editor to a version later than 3.2.6-1 per the vendor advisory.
- If immediate upgrade is not possible, restrict or sanitize untrusted HTML input processed by the editor.
- Apply a strict Content Security Policy to limit script execution in pages embedding the editor.
- Review and limit which users can submit rich content through the editor.
Detection
- Monitor web application logs for editor submissions containing script tags, event handlers, or unusual namespace-like markup.
- Search for anomalous JavaScript execution or DOM changes on pages that embed the Froala editor.
- Alert on outbound requests or session anomalies originating from editor-rendered content.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://froala.com/wysiwyg-editor/ | Vendor Advisory |
| https://labs.bishopfox.com/advisories | Third Party Advisory |
| https://labs.bishopfox.com/advisories/froala-editor-v3.2.6 | Release NotesThird Party Advisory |
| https://froala.com/wysiwyg-editor/ | Vendor Advisory |
| https://labs.bishopfox.com/advisories | Third Party Advisory |
| https://labs.bishopfox.com/advisories/froala-editor-v3.2.6 | Release NotesThird Party Advisory |
Track CVE-2021-28114 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-28114), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.