Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.
{ "versions": [ { "introduced": "8.6.6" }, { "fixed": "9.0.2" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-23849.json"