Baike.dev
All toolsAI codingTrendingOpen sourceNewsSubmit
Log in
Back to tool/Back to issues
#1008·mindoc

MinDoc has a stored XSS vulnerability due to not filtering the onfocus attribute.

Author: sky-teacherCreated Jul 30, 2025Updated Jul 30, 2025

1.Edit the article create an input box with the 'onfocus' attribute

Image
  1. save and Publish
Image

3.Anyone who visits this article and clicks on this input box will trigger XSS. (I used another browser without logging in to test)

Image

Source: mindoc-org/mindoc

View original on GitHubView discussion on GitHub