{ "schema_version": "1.4.0", "id": "GHSA-fq5x-7292-2p5r", "modified": "2025-04-04T18:23:07Z", "published": "2025-04-04T06:34:22Z", "aliases": [ "CVE-2025-3191" ], "summary": "React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button", "details": "All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the