Product
Etherpad Lite version 1.8.14 and earlier is vulnerable to stored XSS via the HTML export feature, allowing attackers to inject malicious payloads into attribute pool values that execute upon viewing exported documents.