Tag
rich-text-editor
Safeguard articles tagged "rich-text-editor" — guides, analysis, and best practices for software supply chain and application security.
3 articles
AppSec
react-quill and Quill: XSS History and Safe Rich-Text Editing
Using Quill in React means understanding CVE-2021-3163, the react-quill maintenance gap, and why editor output must always be sanitized server-side before display.
Aug 14, 20256 min read
Open Source
tinymce-angular Security: What to Know Before You Ship
The tinymce-angular wrapper is thin, but it ships a full rich-text editor whose sanitization gaps have produced real XSS CVEs. Here is how to use it safely.
Jun 24, 20255 min read
Open Source
TinyMCE npm Security: XSS History and Safe Configuration
The tinymce npm package is a capable rich-text editor with a long history of XSS advisories. Keeping it current and configuring it defensively is what keeps it safe.
May 14, 20255 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.