npm›simditor›CVE-2018-190486.1 MEDIUMDOM XSSSimditor allows DOM XSS via an onload attribute within a malformed SVG element.
npm›simditor›CVE-2018-64646.1 MEDIUMCross-site ScriptingSimditor allows XSS via crafted use of svg/onload=alert in a TEXTAREA element.