A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS).
This issue affects Quill: 2.0.3.
{
"cwe_ids": [
"CWE-74",
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-01-16T16:58:02Z",
"nvd_published_at": "2026-01-13T21:15:49Z",
"severity": "LOW"
}