tiptap CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

tiptap vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to tiptap, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-14284 Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanitized user input allowed in setting or toggling links. An attacker can execute arbitrary JavaScript code in the context of the application by injecting a javascript: URL payload into these attributes, which is then triggered either by user interaction. [email protected] 2.0 0.30% 2025-12-09 2026-04-29
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence