
CVE-2026-62324 Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-62324
Post summary
CVE-2026-62324 exposes a flaw in Jodit Editor’s sanitizeHTMLElement where javascript URLs aren’t properly sanitised; the vulnerability is fixed in version 4.12.31.

