Security: udecode/plate
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Improper validation of equation metadata in @platejs/docx-io DOCX exportsGHSA-5pmq-h882-6g62 published
Sep 4, 2026 by zbeyensModerate -
Improper HTML escaping in @platejs/core serialization can enable stored XSSGHSA-fm23-57g4-6m2p published
Sep 4, 2026 by zbeyensModerate -
@platejs/core HTML deserialization can trigger browser behavior during parsingGHSA-qrfj-mgw8-j9c6 published
Sep 4, 2026 by zbeyensModerate -
SSRF with response disclosure in DOCX image embeddingGHSA-4q39-2jhr-7qx8 published
Jul 3, 2026 by zbeyensHigh -
Media embed provider metadata can bypass URL sanitization and execute iframe JavaScriptGHSA-qj6x-xx2h-8hvv published
Jun 14, 2026 by zbeyensHigh -
Arbitrary DOM attributes in element.attributes and leaf.attributesGHSA-73rg-f94j-xvhx published
Sep 20, 2024 by 12joanHigh -
XSS in media embed element when using custom URL parsersGHSA-h3pq-667x-r789 published
Jul 15, 2024 by 12joanHigh -
Links may contain URLs with JavaScript schemeGHSA-4882-hxpr-hrvm published
Jun 9, 2023 by zbeyensHigh
Learn more about advisories related to udecode/plate in the GitHub Advisory Database