CVE-2022-24729
published 2022-03-16CVE-2022-24729: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.45%
82.6th percentile
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor | >= 0 < 4.19.0+dfsg-1 | 4.19.0+dfsg-1 |
| ckeditor | ckeditor | >= 4.0 < 4.18.0 | 4.18.0 |
| ckeditor | ckeditor4 | < 4.18.0 | 4.18.0 |
| ckeditor | ckeditor4 | >= 0 < 4.18.0 | 4.18.0 |
| debian | ckeditor | < ckeditor 4.19.0+dfsg-1 (bookworm) | ckeditor 4.19.0+dfsg-1 (bookworm) |
| debian | ckeditor3 | < ckeditor 4.19.0+dfsg-1 (bookworm) | ckeditor 4.19.0+dfsg-1 (bookworm) |
| drupal | core | >= 8.0.0 < 9.2.15 | 9.2.15 |
| drupal | core | >= 9.3.0 < 9.3.8 | 9.3.8 |
| drupal | drupal | >= 8.0.0 < 9.2.15 | 9.2.15 |
| drupal | drupal | >= 9.3.0 < 9.3.8 | 9.3.8 |
| drupal | drupal_core | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | application_express | < 22.1.1 | 22.1.1 |
| oracle | commerce_merchandising | — | — |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.7.0.0 – 8.1.0.0.0 | — |
| oracle | financial_services_behavior_detection_platform | — | — |
| oracle | financial_services_behavior_detection_platform | — | — |
| oracle | financial_services_behavior_detection_platform | 8.1.1.0 – 8.1.2.1 | — |
| oracle | financial_services_trade-based_anti_money_laundering | — | — |
| oracle | financial_services_trade-based_anti_money_laundering | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_oracle7.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Commerce Merchandising 11.3.2 Core denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle Commerce Merchandising 11.3.2 Core denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability described as critical has been identified in Oracle Commerce Merchandising 11.3.2. Affected by this issue is some unknown functionality of the component Core. The manipulation results in denial of service.
This vulnerability is identified as CVE-2022-24729. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
VulDB
Oracle Financial Services Analytical Applications Infrastructure Others denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle Financial Services Analytical Applications Infrastructure Others denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability classified as critical has been found in Oracle Financial Services Analytical Applications Infrastructure 8.0.7.0/8.1.0.0/8.1.1.0/8.1.2.0/8.1.2.1. This issue affects some unknown processing of the component Others. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2022-24729. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
VulDB
Oracle Agile PLM 9.3.6 WebClient denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle Agile PLM 9.3.6 WebClient denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability was found in Oracle Agile PLM 9.3.6. It has been classified as critical. This issue affects some unknown processing of the component WebClient. This manipulation causes denial of service.
The identification of this vulnerability is CVE-2022-24729. It is possible to initiate the attack remotely. There is no exploit available.
VulDB
Oracle Commerce Guided Search 11.3.2 Workbench denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle Commerce Guided Search 11.3.2 Workbench denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability classified as critical has been found in Oracle Commerce Guided Search 11.3.2. Affected by this issue is some unknown functionality of the component Workbench. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2022-24729. The attack is possible to be carried out remotely. No exploit exists.
VulDB
Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition User Interface denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition User Interface denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability labeled as critical has been found in Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition 8.0.7.0/8.0.8.0. This issue affects some unknown processing of the component User Interface. Executing a manipulation can lead to denial of service.
This vulnerability is registered as CVE-2022-24729. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
VulDB
Oracle Financial Services Behavior Detection Platform 8.0.7.0/8.0.8.0/8.1.1.0/8.1.2.1 Third Party denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle Financial Services Behavior Detection Platform 8.0.7.0/8.0.8.0/8.1.1.0/8.1.2.1 Third Party denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability, which was classified as critical, has been found in Oracle Financial Services Behavior Detection Platform 8.0.7.0/8.0.8.0/8.1.1.0/8.1.2.1. The affected element is an unknown function of the component Third Party. This manipulation causes denial of service.
This vulnerability is handled as CVE-2022-24729. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
VulDB
Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59 Rich Text Editor denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59 Rich Text Editor denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability has been found in Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59 and classified as critical. Impacted is an unknown function of the component Rich Text Editor. The manipulation leads to denial of service.
This vulnerability is listed as CVE-2022-24729. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
VulDB
Oracle WebCenter Portal 12.2.1.3.0/12.2.1.4.0 Security Framework denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle WebCenter Portal 12.2.1.3.0/12.2.1.4.0 Security Framework denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability identified as critical has been detected in Oracle WebCenter Portal 12.2.1.3.0/12.2.1.4.0. This affects an unknown function of the component Security Framework. This manipulation causes denial of service.
The identification of this vulnerability is CVE-2022-24729. It is possible to initiate the attack remotely. There is no exploit available.
VulDB
Oracle Siebel UI Framework up to 22.8 Open UI denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle Siebel UI Framework up to 22.8 Open UI denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability described as critical has been identified in Oracle Siebel UI Framework up to 22.8. This affects an unknown function of the component Open UI. The manipulation results in denial of service.
This vulnerability is reported as CVE-2022-24729. The attack can be launched remotely. No exploit exists.
VulDB
Oracle WebCenter Sites 12.2.1.3.0/12.2.1.4.0 denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle WebCenter Sites 12.2.1.3.0/12.2.1.4.0 denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability described as critical has been identified in Oracle WebCenter Sites 12.2.1.3.0/12.2.1.4.0. Affected by this vulnerability is an unknown functionality of the component WebCenter Sites. Executing a manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2022-24729. The attack can be launched remotely. No exploit exists.
VulDB
Oracle Application Express User Account denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle Application Express User Account denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability, which was classified as critical, has been found in Oracle Application Express. This impacts an unknown function of the component User Account. The manipulation leads to denial of service.
This vulnerability is documented as CVE-2022-24729. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
VulDB
Oracle Financial Services Enterprise Case Management up to 8.1.2.1 Installers denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle Financial Services Enterprise Case Management up to 8.1.2.1 Installers denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability categorized as critical has been discovered in Oracle Financial Services Enterprise Case Management up to 8.1.2.1. This affects an unknown part of the component Installers. Such manipulation leads to denial of service.
This vulnerability is listed as CVE-2022-24729. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
VulDB
Oracle Business Intelligence Enterprise Edition 5.9.0.0/6.4.0.0 Analytics Server denial of service (EUVD-2022-29580 / Nessus ID 211412)
vuldb·2026-05-04·CVSS 7.5
CVE-2022-24729 [HIGH] Oracle Business Intelligence Enterprise Edition 5.9.0.0/6.4.0.0 Analytics Server denial of service (EUVD-2022-29580 / Nessus ID 211412)
A vulnerability classified as critical was found in Oracle Business Intelligence Enterprise Edition 5.9.0.0/6.4.0.0. Affected is an unknown function of the component Analytics Server. Executing a manipulation can lead to denial of service.
This vulnerability is registered as CVE-2022-24729. It is possible to launch the attack remotely. No exploit is available.
OSV
CVE-2022-24728: The Drupal project uses the [CKEditor](https://github
osv·2022-03-16·CVSS 5.4
CVE-2022-24728 [MEDIUM] CVE-2022-24728: The Drupal project uses the [CKEditor](https://github
The Drupal project uses the [CKEditor](https://github.com/ckeditor/ckeditor4) library for WYSIWYG editing. CKEditor has released [a security update that impacts Drupal](https://ckeditor.com/blog/ckeditor-4.18.0-browser-bugfix-and-security-patches/).
Vulnerabilities are possible if Drupal is configured to allow use of the CKEditor library for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access.
For more information, see CKEditor's security advisories:
* [CVE-2022-24728: HTML processing vulnerability allowing to execute JavaScript code](https://github.com/ckedito
OSV
Cross-site Scripting in CKEditor4
osv·2022-03-16
CVE-2022-24728 [MEDIUM] Cross-site Scripting in CKEditor4
Cross-site Scripting in CKEditor4
### Affected packages
The vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4.
### Impact
A potential vulnerability has been discovered in CKEditor 4 HTML processing core module. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.18.0.
### Patches
The problem has been recognized and patched. The fix will be available in version 4.18.0.
### For more information
Email us at [email protected] if you have any questions or comments about this advisory.
### Acknowledgements
The CKEditor 4 team would like to thank GHSL team member Kevin Backhouse ([@kevinba
OSV
CVE-2022-24729: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor
osv·2022-03-16·CVSS 7.5
CVE-2022-24729 [HIGH] CVE-2022-24729: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.
Oracle
Oracle Oracle Commerce Risk Matrix: Workbench (CKEditor) — CVE-2022-24729
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-24729 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Workbench (CKEditor) — CVE-2022-24729
Oracle Oracle Commerce Risk Matrix: Workbench (CKEditor) vulnerability
CVE: CVE-2022-24729
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Analytics Server (CKEditor) — CVE-2022-24729
vendor_oracle·2022-10-15·CVSS 7.5
CVE-2022-24729 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Analytics Server (CKEditor) — CVE-2022-24729
Oracle Oracle Fusion Middleware Risk Matrix: Analytics Server (CKEditor) vulnerability
CVE: CVE-2022-24729
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) — CVE-2022-24729
vendor_oracle·2022-07-15·CVSS 5.7
CVE-2022-24729 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) — CVE-2022-24729
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) vulnerability
CVE: CVE-2022-24729
CVSS: 5.7
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Drupal
Drupal core - Moderately critical - Third-party libraries - SA-CORE-2022-005
vendor_drupal·2022-03-16·CVSS 5.4
CVE-2022-24728 [MEDIUM] Drupal core - Moderately critical - Third-party libraries - SA-CORE-2022-005
Title: Drupal core - Moderately critical - Third-party libraries - SA-CORE-2022-005
Vulnerability Type: Third-party libraries
Description: The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal . Vulnerabilities are possible if Drupal is configured to allow use of the CKEditor library for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access. For more information, see CKEditor's security advisories: CVE-2022-24728: HTML processing vulnerability allowing to execute JavaScript code CVE-2022-24729
Debian
CVE-2022-24729: ckeditor - CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 ...
vendor_debian·2022·CVSS 6.5
CVE-2022-24729 [MEDIUM] CVE-2022-24729: ckeditor - CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 ...
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.
Scope: local
bookworm: resolved (fixed in 4.19.0+dfsg-1)
bullseye: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://ckeditor.com/cke4/release/CKEditor-4.18.0https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-f6rf-9m92-x2hhhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VR76VBN5GW5QUBJFHVXRX36UZ6YTCMW6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WOZGMCYDB2OKKULFXZKM6V7JJW4ZZHJP/https://www.drupal.org/sa-core-2022-005https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://ckeditor.com/cke4/release/CKEditor-4.18.0https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-f6rf-9m92-x2hhhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VR76VBN5GW5QUBJFHVXRX36UZ6YTCMW6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WOZGMCYDB2OKKULFXZKM6V7JJW4ZZHJP/https://www.drupal.org/sa-core-2022-005https://www.oracle.com/security-alerts/cpujul2022.html
2022-03-16
Published