CVE-2021-30109

MEDIUM

Froala Editor 3.2.6 - Stored Cross-Site Scripting via Hyperlink Creation Module

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-30109. PoCs published by Hackdwerg.

AI-analyzed exploit summary The repository contains only a README describing CVE-2021-30109, an XSS vulnerability in Froala WYSIWYG Editor 3.2.6, but lacks any functional exploit code or technical details. The PoC is marked as 'Coming soon,' indicating incomplete content.

Description

Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creation module.

Exploits (1)

nomisec STUB 1 stars
by Hackdwerg · poc
https://github.com/Hackdwerg/CVE-2021-30109

The repository contains only a README describing CVE-2021-30109, an XSS vulnerability in Froala WYSIWYG Editor 3.2.6, but lacks any functional exploit code or technical details. The PoC is marked as 'Coming soon,' indicating incomplete content.

Classification
Stub 90%
Attack Type
Xss
Complexity
Theoretical
Reliability
Theoretical
Target: Froala WYSIWYG Editor 3.2.6
No auth needed
Prerequisites: Access to a vulnerable instance of Froala WYSIWYG Editor
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Product x_refsource_misc
http://froala.com

Scores

CVSS v3 6.1
EPSS 0.0031
EPSS Percentile 54.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
froala/froala_editor 3.2.6
npm/froala-editor 0npm
Published Apr 05, 2021
Tracked Since Feb 18, 2026