CVE-2022-24728
published 2022-03-16CVE-2022-24728: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.19%
64.7th percentile
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor | >= 0 < 4.19.0+dfsg-1 | 4.19.0+dfsg-1 |
| ckeditor | ckeditor | >= 0 < 4.5.7+dfsg-2ubuntu0.16.04.1~esm2 | 4.5.7+dfsg-2ubuntu0.16.04.1~esm2 |
| ckeditor | ckeditor | >= 0 < 4.5.7+dfsg-2ubuntu0.18.04.1+esm1 | 4.5.7+dfsg-2ubuntu0.18.04.1+esm1 |
| ckeditor | ckeditor | >= 0 < 4.12.1+dfsg-1ubuntu0.1+esm1 | 4.12.1+dfsg-1ubuntu0.1+esm1 |
| ckeditor | ckeditor | >= 0 < 4.16.2+dfsg-1ubuntu0.1~esm1 | 4.16.2+dfsg-1ubuntu0.1~esm1 |
| ckeditor | ckeditor | >= 0 < 4.22.1+dfsg1-2ubuntu0.24.04.1~esm1 | 4.22.1+dfsg1-2ubuntu0.24.04.1~esm1 |
| ckeditor | ckeditor | >= 4.0 < 4.18.0 | 4.18.0 |
| ckeditor | ckeditor4 | < 4.18.0 | 4.18.0 |
| ckeditor | ckeditor4 | >= 0 < 4.18.0 | 4.18.0 |
| debian | ckeditor | < ckeditor 4.19.0+dfsg-1 (bookworm) | ckeditor 4.19.0+dfsg-1 (bookworm) |
| debian | ckeditor3 | < ckeditor 4.19.0+dfsg-1 (bookworm) | ckeditor 4.19.0+dfsg-1 (bookworm) |
| drupal | core | >= 8.0.0 < 9.2.15 | 9.2.15 |
| drupal | core | >= 9.3.0 < 9.3.8 | 9.3.8 |
| drupal | drupal | >= 8.0.0 < 9.2.15 | 9.2.15 |
| drupal | drupal | >= 9.3.0 < 9.3.8 | 9.3.8 |
| drupal | drupal_core | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | application_express | < 22.1.1 | 22.1.1 |
| oracle | commerce_merchandising | — | — |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.7.0.0 – 8.1.0.0.0 | — |
| oracle | financial_services_behavior_detection_platform | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_ubuntu5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CKEditor vulnerabilities
vendor_ubuntu·2025-02-06·CVSS 5.4
CVE-2024-24816 [MEDIUM] CKEditor vulnerabilities
Title: CKEditor vulnerabilities
Summary: Several security issues were fixed in CKEditor.
Kevin Backhouse discovered that CKEditor did not properly sanitize HTML
content. An attacker could possibly use this issue to perform cross site
scripting and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-24728)
It was discovered that CKEditor did not properly handle the creation of
editor instances in the Iframe Dialog and Media Embed packages. An
attacker could possibly use this issue to perform cross site scripting
and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2023-28439)
It was discovered that CKEditor did not
Drupal
Drupal core - Moderately critical - Third-party libraries - SA-CORE-2022-005
vendor_drupal·2022-03-16·CVSS 5.4
CVE-2022-24728 [MEDIUM] Drupal core - Moderately critical - Third-party libraries - SA-CORE-2022-005
Title: Drupal core - Moderately critical - Third-party libraries - SA-CORE-2022-005
Vulnerability Type: Third-party libraries
Description: The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal . Vulnerabilities are possible if Drupal is configured to allow use of the CKEditor library for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access. For more information, see CKEditor's security advisories: CVE-2022-24728: HTML processing vulnerability allowing to execute JavaScript code CVE-2022-24729
Debian
CVE-2022-24728: ckeditor - CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerab...
vendor_debian·2022·CVSS 5.4
CVE-2022-24728 [MEDIUM] CVE-2022-24728: ckeditor - CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerab...
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.
Scope: local
bookworm: resolved (fixed in 4.19.0+dfsg-1)
bullseye: open
OSV
ckeditor vulnerabilities
osv·2025-02-06·CVSS 5.4
CVE-2022-24728 [MEDIUM] ckeditor vulnerabilities
ckeditor vulnerabilities
Kevin Backhouse discovered that CKEditor did not properly sanitize HTML
content. An attacker could possibly use this issue to perform cross site
scripting and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-24728)
It was discovered that CKEditor did not properly handle the creation of
editor instances in the Iframe Dialog and Media Embed packages. An
attacker could possibly use this issue to perform cross site scripting
and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2023-28439)
It was discovered that CKEditor did not properly handle parsing HTML
content. An attacker could possibly
GHSA
Cross-site Scripting in CKEditor4
ghsa·2022-03-16
CVE-2022-24728 [MEDIUM] CWE-79 Cross-site Scripting in CKEditor4
Cross-site Scripting in CKEditor4
### Affected packages
The vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4.
### Impact
A potential vulnerability has been discovered in CKEditor 4 HTML processing core module. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.18.0.
### Patches
The problem has been recognized and patched. The fix will be available in version 4.18.0.
### For more information
Email us at [email protected] if you have any questions or comments about this advisory.
### Acknowledgements
The CKEditor 4 team would like to thank GHSL team member Kevin Backhouse ([@kevinba
OSV
CVE-2022-24728: The Drupal project uses the [CKEditor](https://github
osv·2022-03-16·CVSS 5.4
CVE-2022-24728 [MEDIUM] CVE-2022-24728: The Drupal project uses the [CKEditor](https://github
The Drupal project uses the [CKEditor](https://github.com/ckeditor/ckeditor4) library for WYSIWYG editing. CKEditor has released [a security update that impacts Drupal](https://ckeditor.com/blog/ckeditor-4.18.0-browser-bugfix-and-security-patches/).
Vulnerabilities are possible if Drupal is configured to allow use of the CKEditor library for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access.
For more information, see CKEditor's security advisories:
* [CVE-2022-24728: HTML processing vulnerability allowing to execute JavaScript code](https://github.com/ckedito
OSV
Cross-site Scripting in CKEditor4
osv·2022-03-16
CVE-2022-24728 [MEDIUM] Cross-site Scripting in CKEditor4
Cross-site Scripting in CKEditor4
### Affected packages
The vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4.
### Impact
A potential vulnerability has been discovered in CKEditor 4 HTML processing core module. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.18.0.
### Patches
The problem has been recognized and patched. The fix will be available in version 4.18.0.
### For more information
Email us at [email protected] if you have any questions or comments about this advisory.
### Acknowledgements
The CKEditor 4 team would like to thank GHSL team member Kevin Backhouse ([@kevinba
OSV
CVE-2022-24728: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor
osv·2022-03-16·CVSS 5.4
CVE-2022-24728 [MEDIUM] CVE-2022-24728: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://ckeditor.com/cke4/release/CKEditor-4.18.0https://github.com/ckeditor/ckeditor4/commit/d158413449692d920a778503502dcb22881bc949https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-4fc4-4p5g-6w89https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VR76VBN5GW5QUBJFHVXRX36UZ6YTCMW6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WOZGMCYDB2OKKULFXZKM6V7JJW4ZZHJP/https://www.drupal.org/sa-core-2022-005https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://ckeditor.com/cke4/release/CKEditor-4.18.0https://github.com/ckeditor/ckeditor4/commit/d158413449692d920a778503502dcb22881bc949https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-4fc4-4p5g-6w89https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VR76VBN5GW5QUBJFHVXRX36UZ6YTCMW6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WOZGMCYDB2OKKULFXZKM6V7JJW4ZZHJP/https://www.drupal.org/sa-core-2022-005https://www.oracle.com/security-alerts/cpujul2022.html
2022-03-16
Published