Vendor
high
advisory
SSRF and Response Disclosure in @platejs/docx-io
1 CVEThe @platejs/docx-io library is vulnerable to Server-Side Request Forgery (SSRF) and response disclosure, allowing attackers to probe internal networks via malicious HTML image embeddings.
@platejs/docx-io
web-vulnerability
ssrf
data-exfiltration
1c
high
advisory
Cross-Site Scripting Vulnerability in Plate Media Embed Renderer
1 TTP 1 CVEA vulnerability in the Plate @platejs/media package allows attackers to bypass URL sanitization and achieve Cross-Site Scripting (XSS) by embedding malicious JavaScript URIs in media documents (CVE-2026-55596).
@platejs/media
xss
injection
web-application
cve-2026-55596
1t
1c