Search/CVE-2026-65841
CVE

CVE-2026-65841

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This issue is fixed in version 4.13.6.

CVSS v3.1
EPSS
0.40%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 26, 2026Sep 11, 2026
0.08pp
0.32% → 0.40% over 2 tracked changes
Connections
1 relationships
Timeline
disclosure → media coverage
Jul 31, 2026
Disclosure — published as a CVE record. · last revised by NVD Sep 9, 2026