CVE-2020-9281
published 2020-03-07CVE-2020-9281: A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
4.31%
90.5th percentile
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor | >= 0 < 4.5.7+dfsg-2ubuntu0.18.04.1 | 4.5.7+dfsg-2ubuntu0.18.04.1 |
| ckeditor | ckeditor | >= 0 < 4.12.1+dfsg-1ubuntu0.1 | 4.12.1+dfsg-1ubuntu0.1 |
| ckeditor | ckeditor | >= 0 < 4.5.7+dfsg-2ubuntu0.16.04.1~esm1 | 4.5.7+dfsg-2ubuntu0.16.04.1~esm1 |
| ckeditor | ckeditor | >= 4.0 < 4.14 | 4.14 |
| ckeditor | ckeditor4 | >= 0 < 4.14.0 | 4.14.0 |
| drupal | drupal | >= 8.7.0 < 8.7.12 | 8.7.12 |
| drupal | drupal | >= 8.8.0 < 8.8.4 | 8.8.4 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | 6.0.0 – 6.2.9 | — |
| fortinet | fortianalyzer | 6.4.0 – 6.4.8 | — |
| fortinet | fortianalyzer | 7.0.0 – 7.0.4 | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | 6.0.0 – 6.2.9 | — |
| fortinet | fortimanager | 6.4.0 – 6.4.8 | — |
| fortinet | fortimanager | 7.0.0 – 7.0.4 | — |
| oracle | agile_product_lifecycle_management | — | — |
| oracle | agile_product_lifecycle_management | — | — |
| oracle | application_express | < 20.2 | 20.2 |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_oracle6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Banking Enterprise Default Management 2.7.0 Collections cross site scripting
vuldb·2026-08-26·CVSS 6.1
CVE-2020-9281 [MEDIUM] Oracle Banking Enterprise Default Management 2.7.0 Collections cross site scripting
A vulnerability marked as critical has been reported in Oracle Banking Enterprise Default Management 2.7.0. Impacted is an unknown function of the component Collections. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2020-9281. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
VulDB
Oracle Agile PLM 9.3.5/9.3.6 Security cross site scripting
vuldb·2026-08-26·CVSS 6.1
CVE-2020-9281 [MEDIUM] Oracle Agile PLM 9.3.5/9.3.6 Security cross site scripting
A vulnerability classified as critical was found in Oracle Agile PLM 9.3.5/9.3.6. Impacted is an unknown function of the component Security. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2020-9281. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
VulDB
Oracle PeopleSoft Enterprise PeopleTools 8.56/8.57/8.58 Rich Text Editor cross site scripting
vuldb·2026-08-26·CVSS 6.1
CVE-2020-9281 [MEDIUM] Oracle PeopleSoft Enterprise PeopleTools 8.56/8.57/8.58 Rich Text Editor cross site scripting
A vulnerability labeled as critical has been found in Oracle PeopleSoft Enterprise PeopleTools 8.56/8.57/8.58. This vulnerability affects unknown code of the component Rich Text Editor. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2020-9281. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
VulDB
Oracle JD Edwards EnterpriseOne Tools up to 9.2.5.1 Web Runtime cross site scripting
vuldb·2026-08-26·CVSS 6.1
CVE-2020-9281 [MEDIUM] Oracle JD Edwards EnterpriseOne Tools up to 9.2.5.1 Web Runtime cross site scripting
A vulnerability classified as critical has been found in Oracle JD Edwards EnterpriseOne Tools up to 9.2.5.1. Affected is an unknown function of the component Web Runtime. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2020-9281. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
VulDB
Oracle WebCenter Portal 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Blogs/Wikis cross site scripting
vuldb·2026-08-26·CVSS 6.1
CVE-2020-9281 [MEDIUM] Oracle WebCenter Portal 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Blogs/Wikis cross site scripting
A vulnerability, which was classified as critical, has been found in Oracle WebCenter Portal 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0. The affected element is an unknown function of the component Blogs/Wikis. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2020-9281. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
VulDB
Oracle Database Server up to 20.1 Oracle Application Express cross site scripting
vuldb·2026-08-26·CVSS 6.1
CVE-2020-9281 [MEDIUM] Oracle Database Server up to 20.1 Oracle Application Express cross site scripting
A vulnerability described as critical has been identified in Oracle Database Server up to 20.1. Affected is an unknown function of the component Oracle Application Express. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2020-9281. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
VulDB
Oracle Siebel Apps up to 21.0 Customizable Prod/Configurator cross site scripting
vuldb·2026-08-26·CVSS 6.1
CVE-2020-9281 [MEDIUM] Oracle Siebel Apps up to 21.0 Customizable Prod/Configurator cross site scripting
A vulnerability marked as critical has been reported in Oracle Siebel Apps up to 21.0. Affected is an unknown function of the component Customizable Prod/Configurator. Performing a manipulation results in cross site scripting.
This vulnerability is reported as CVE-2020-9281. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
GHSA-vghm-mjgx-gf75: An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6
ghsa_unreviewed·2022-11-02·CVSS 6.1
CVE-2022-39950 [MEDIUM] CWE-79 GHSA-vghm-mjgx-gf75: An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6
An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described in CVE-2020-9281.
OSV
ckeditor vulnerabilities
osv·2022-03-23·CVSS 6.1
CVE-2018-9861 [MEDIUM] ckeditor vulnerabilities
ckeditor vulnerabilities
USN-5340-1 fixed several vulnerabilities in CKEditor.
This update provides the fixes for CVE-2018-9861, CVE-2020-9281,
CVE-2021-32809, CVE-2021-33829 and CVE-2021-37695 for Ubuntu 16.04 ESM.
Original advisory details:
Kyaw Min Thein discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue
to execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS. (CVE-2018-9861)
Micha Bentkowski discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-9281)
Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
ex
OSV
ckeditor vulnerabilities
osv·2022-03-22·CVSS 6.1
CVE-2018-9861 [MEDIUM] ckeditor vulnerabilities
ckeditor vulnerabilities
Kyaw Min Thein discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue
to execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS. (CVE-2018-9861)
Micha Bentkowski discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-9281)
Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 21.10. (CVE-2021-32808)
Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
inject arbitrary code
GHSA
CKEditor 4.0 vulnerability in the HTML Data Processor
ghsa·2021-05-07
CVE-2020-9281 [MEDIUM] CWE-79 CKEditor 4.0 vulnerability in the HTML Data Processor
CKEditor 4.0 vulnerability in the HTML Data Processor
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14.0 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
OSV
CKEditor 4.0 vulnerability in the HTML Data Processor
osv·2021-05-07
CVE-2020-9281 [MEDIUM] CKEditor 4.0 vulnerability in the HTML Data Processor
CKEditor 4.0 vulnerability in the HTML Data Processor
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14.0 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
OSV
CVE-2020-9281: A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4
osv·2020-03-07·CVSS 6.1
CVE-2020-9281 [MEDIUM] CVE-2020-9281: A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Fortinet
An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAn...
vendor_fortinet·2022-11-02·CVSS 8.0
CVE-2022-39950 [MEDIUM] CWE-79 An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAn...
FG-IR-21-228: An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAn...
An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described in CVE-2020-9281.
CVEs: CVE-2022-39950
CWEs: CWE-79
CVSS: 8.0 (high)
Affected products: FortiAnalyzer, FortiManager
Ubuntu
CKEditor vulnerabilities
vendor_ubuntu·2022-03-23·CVSS 6.1
CVE-2021-32809 [MEDIUM] CKEditor vulnerabilities
Title: CKEditor vulnerabilities
Summary: Several security issues were fixed in CKEditor.
USN-5340-1 fixed several vulnerabilities in CKEditor.
This update provides the fixes for CVE-2018-9861, CVE-2020-9281,
CVE-2021-32809, CVE-2021-33829 and CVE-2021-37695 for Ubuntu 16.04 ESM.
Original advisory details:
Kyaw Min Thein discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue
to execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS. (CVE-2018-9861)
Micha Bentkowski discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-9281)
Anton Subbotin discovered that CKEditor incorrectly handle
Ubuntu
CKEditor vulnerabilities
vendor_ubuntu·2022-03-22·CVSS 6.1
CVE-2020-9281 [MEDIUM] CKEditor vulnerabilities
Title: CKEditor vulnerabilities
Summary: Several security issues were fixed in CKEditor.
Kyaw Min Thein discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue
to execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS. (CVE-2018-9861)
Micha Bentkowski discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-9281)
Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 21.10. (CVE-2021-32808)
Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. A
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Collections (CKEditor) — CVE-2020-9281
vendor_oracle·2022-01-15·CVSS 6.1
CVE-2020-9281 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Collections (CKEditor) — CVE-2020-9281
Oracle Oracle Financial Services Applications Risk Matrix: Collections (CKEditor) vulnerability
CVE: CVE-2020-9281
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle JD Edwards Risk Matrix: Web Runtime (CKEditor) — CVE-2020-9281
vendor_oracle·2021-04-15·CVSS 6.1
CVE-2020-9281 [MEDIUM] Oracle Oracle JD Edwards Risk Matrix: Web Runtime (CKEditor) — CVE-2020-9281
Oracle Oracle JD Edwards Risk Matrix: Web Runtime (CKEditor) vulnerability
CVE: CVE-2020-9281
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Rich Text Editor (CKEditor) — CVE-2020-9281
vendor_oracle·2021-01-15·CVSS 6.1
CVE-2020-9281 [MEDIUM] Oracle Oracle PeopleSoft Risk Matrix: Rich Text Editor (CKEditor) — CVE-2020-9281
Oracle Oracle PeopleSoft Risk Matrix: Rich Text Editor (CKEditor) vulnerability
CVE: CVE-2020-9281
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Application Express — CVE-2020-9281
vendor_oracle·2020-10-15·CVSS 5.4
CVE-2020-9281 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Oracle Application Express — CVE-2020-9281
Oracle Oracle Database Server Risk Matrix: Oracle Application Express vulnerability
CVE: CVE-2020-9281
CVSS: 5.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-9281 ckeditor: XSS in the HTML Data Processor allows remote attackers to inject arbitrary web script through a crafted "protected" comment [fedora-all]
bugzilla·2020-03-18·CVSS 6.1
CVE-2020-9281 [MEDIUM] CVE-2020-9281 ckeditor: XSS in the HTML Data Processor allows remote attackers to inject arbitrary web script through a crafted "protected" comment [fedora-all]
CVE-2020-9281 ckeditor: XSS in the HTML Data Processor allows remote attackers to inject arbitrary web script through a crafted "protected" comment [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog a
Bugzilla
CVE-2020-9281 ckeditor: XSS in the HTML Data Processor allows remote attackers to inject arbitrary web script through a crafted "protected" comment
bugzilla·2020-03-18·CVSS 6.1
CVE-2020-9281 [MEDIUM] CVE-2020-9281 ckeditor: XSS in the HTML Data Processor allows remote attackers to inject arbitrary web script through a crafted "protected" comment
CVE-2020-9281 ckeditor: XSS in the HTML Data Processor allows remote attackers to inject arbitrary web script through a crafted "protected" comment
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Reference:
https://github.com/ckeditor/ckeditor4
Discussion:
Created ckeditor tracking bugs for this issue:
Affects: epel-all [bug 1814827]
Affects: fedora-all [bug 1814826]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Bugzilla
CVE-2020-9281 ckeditor: XSS in the HTML Data Processor allows remote attackers to inject arbitrary web script through a crafted "protected" comment [epel-all]
bugzilla·2020-03-18·CVSS 6.1
CVE-2020-9281 [MEDIUM] CVE-2020-9281 ckeditor: XSS in the HTML Data Processor allows remote attackers to inject arbitrary web script through a crafted "protected" comment [epel-all]
CVE-2020-9281 ckeditor: XSS in the HTML Data Processor allows remote attackers to inject arbitrary web script through a crafted "protected" comment [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and t
https://github.com/ckeditor/ckeditor4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7OJ4BSS3VEAEXPNSOOUAXX6RDNECGZNO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L322YA73LCV3TO7ORY45WQDAFJVNKXBE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M4HHYQ6N452XTCIROFMJOTYEUWSB6FR4/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://github.com/ckeditor/ckeditor4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7OJ4BSS3VEAEXPNSOOUAXX6RDNECGZNO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L322YA73LCV3TO7ORY45WQDAFJVNKXBE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M4HHYQ6N452XTCIROFMJOTYEUWSB6FR4/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-03-07
Published