Vulnerability Description
SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control configuration options passed to sceditor.create(), like emoticons, charset, etc. then it's possible for them to trigger an XSS attack due to lack of sanitisation of configuration options. This vulnerability is fixed in 3.2.1.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sceditor | Sceditor | < 3.2.1 |
Related Weaknesses (CWE)
References
- https://github.com/samclarke/SCEditor/commit/5733aed4f0e257cb78e1ba191715fc458cbPatch
- https://github.com/samclarke/SCEditor/security/advisories/GHSA-25fq-6qgg-qpj8ExploitVendor Advisory
FAQ
What is CVE-2026-25581?
CVE-2026-25581 is a vulnerability with a CVSS score of 5.4 (MEDIUM). SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control configuration options passed to sceditor.create(), like emoticons, charset, etc. then ...
How severe is CVE-2026-25581?
CVE-2026-25581 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-25581?
Check the references section above for vendor advisories and patch information. Affected products include: Sceditor Sceditor.