PT-2026-93760 · Plate · Plate

CVE-2026-88976

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Plate versions prior to 53.3.11 Plate versions 54.0.0-beta.0 through 54.0.0-beta.1
Description Core HTML deserialization APIs parse supplied HTML strings within the active document. When untrusted or cross-user HTML is passed to these APIs, specific HTML attributes can trigger browser behavior before the content is converted into editor nodes. This allows an attacker to execute arbitrary script in the application origin when a user loads the deserialized content.
Recommendations Update to version 53.3.11 or later. Install the fixed stable line. Sanitize untrusted HTML before rendering it.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88976
GHSA-QRFJ-MGW8-J9C6

Affected Products

Plate