Overview
What is CVE-2023-3978?
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
Source: NVD
Vulnerability intelligence
CVE-2023-3978 and is rated Medium severity with a CVSS score of 6.1. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
Source: NVD