cbcvebase.

Ckeditor Ckeditor4 vulnerabilities

17 known vulnerabilities affecting ckeditor/ckeditor4.

Total CVEs
17
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM15LOW1

Vulnerabilities

Page 1 of 1
CVE-2021-33829P3MEDIUMPoC≥ 4.14.0, < 4.16.12021-06-21
CVE-2021-33829 [MEDIUM] CWE-79 ckeditor4 vulnerable to cross-site scripting ckeditor4 vulnerable to cross-site scripting A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because `--!>` is mishandled.
ghsaosv
CVE-2022-24729P3HIGHCVSS 7.5fixed in 4.18.02022-03-16
CVE-2022-24729 [HIGH] CWE-400 CVE-2022-24729: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.1 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0.
nvd
CVE-2021-26272P4MEDIUM≥ 0, < 4.16.02021-10-13
CVE-2021-26272 [MEDIUM] CWE-829 Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4 Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4 It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
ghsaosv
CVE-2024-24816P4MEDIUMCVSS 6.1fixed in 4.24.0-lts2024-02-07
CVE-2024-24816 [MEDIUM] CWE-79 CVE-2024-24816: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnera CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior to 4.24.0-lts in samples that use the `preview` feature. All integrators that use these samples in the production code can be affected. The vulnerability allows an attacker to execute JavaScrip
ghsanvdosv
CVE-2024-43407P4MEDIUMCVSS 6.1fixed in 4.25.0-lts2024-08-21
CVE-2024-43407 [MEDIUM] CWE-79 CVE-2024-43407: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in CKEditor 4 Code Snippet GeSHi plugin. The vulnerability allowed a reflected XSS attack by exploiting a flaw in the GeSHi syntax highlighter library hosted by the victim. The GeSHi library was included as a vendor dependency in CKEdito
ghsanvdosv
CVE-2021-32809P4MEDIUMCVSS 5.4v>= 4.5.2, < 4.16.22021-08-12
CVE-2021-32809 [MEDIUM] CWE-94 CVE-2021-32809: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all
ghsanvdosv
CVE-2021-41165P4MEDIUMCVSS 5.4fixed in 4.17.02021-11-17
CVE-2021-41165 [MEDIUM] CWE-79 CVE-2021-41165: CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discov CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users usi
ghsanvdosv
CVE-2021-32808P4MEDIUMCVSS 5.4v>= 4.13.0, < 4.16.22021-08-12
CVE-2021-32808 [MEDIUM] CWE-79 CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been d ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEdit
ghsanvdosv
CVE-2020-9281P4MEDIUM≥ 0, < 4.14.02021-05-07
CVE-2020-9281 [MEDIUM] CWE-79 CKEditor 4.0 vulnerability in the HTML Data Processor CKEditor 4.0 vulnerability in the HTML Data Processor A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14.0 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
ghsaosv
CVE-2021-37695P4MEDIUMCVSS 5.4fixed in 4.16.22021-08-13
CVE-2021-37695 [MEDIUM] CWE-79 CVE-2021-37695: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEdi
ghsanvdosv
CVE-2021-41164P4MEDIUMCVSS 5.4fixed in 4.17.02021-11-17
CVE-2021-41164 [MEDIUM] CWE-79 CVE-2021-41164: CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been disco CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users us
ghsanvdosv
CVE-2022-24728P4MEDIUMCVSS 5.4fixed in 4.18.02022-03-16
CVE-2022-24728 [MEDIUM] CWE-79 CVE-2022-24728: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been disco CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. T
ghsanvdosv
CVE-2023-28439P4MEDIUMCVSS 6.1fixed in 4.21.02023-03-22
CVE-2023-28439 [MEDIUM] CWE-79 CVE-2023-28439: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnera CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed packages. The vulnerability may trigger a JavaScript code after fulfilling special conditions: using one of the affected packages on a web page with missing proper Content Security Poli
nvd
CVE-2024-24815P4MEDIUMCVSS 6.1fixed in 4.24.0-lts2024-02-07
CVE-2024-24815 [MEDIUM] CWE-79 CVE-2024-24815: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnera CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0-lts. It may affect all editor instances that enabled full-page editing mode or enabled CDATA elements in Advanced Content Filtering configuration (defau
ghsanvdosv
CVE-2020-27193P4MEDIUM≥ 0, < 4.15.12022-05-24
CVE-2020-27193 [MEDIUM] CWE-79 Improper Neutralization of Input During Web Page Generation in CKEditor4 Improper Neutralization of Input During Web Page Generation in CKEditor4 A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
ghsaosv
CVE-2023-4771P4MEDIUM≥ 0, < 4.24.0-lts2024-02-07
CVE-2023-4771 [MEDIUM] CWE-79 CKEditor cross-site scripting vulnerability in AJAX sample CKEditor cross-site scripting vulnerability in AJAX sample ### Affected packages The vulnerability has been discovered in the AJAX sample available at the `samples/old/ajax.html` file location. All integrators that use that sample in the production code can be affected. ### Impact A potential vulnerability has been discovered in one of CKEditor's 4 samples that are shipped with production code. The vulner
ghsaosv
CVE-2024-43411P4LOWCVSS 3.1v>= 4.22.0, < 4.25.0-lts2024-08-21
CVE-2024-43411 [LOW] CWE-79 CVE-2024-43411: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability ha CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. The issue impacts only editor instan
ghsanvdosv
Ckeditor Ckeditor4 vulnerabilities | cvebase