Skip to main content

Vendor archive

ckeditor CVEs

Beta · best-effort

34 CVEs tagged to vendor ckeditor1 Critical, 5 High, 28 Medium, 0 Low, 0 Unrated.

CVE-2026-28343

Published Mar 5, 2026

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-61261

Published Nov 7, 2025

A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute arbitrary code in the context of a user's browser via inject…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-45613

Published Sep 25, 2024

CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipbo…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43407

Published Aug 21, 2024

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in CKEditor 4 Code Snippet GeSHi plugin. The vulnerability allo…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24816

Published Feb 7, 2024

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior to 4.24.0-lts in sam…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24815

Published Feb 7, 2024

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEdi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31541

Published Jun 13, 2023

A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be upl…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-28439

Published Mar 22, 2023

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed packages. Th…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48110

Published Feb 13, 2023

CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24729

Published Mar 16, 2022

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows a…

CVSS 6.5 · Medium

CVE-2022-24728

Published Mar 16, 2022

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKE…

CVSS 5.4 · Medium

CVE-2021-41165

Published Nov 17, 2021

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEd…

CVSS 8.2 · High

CVE-2021-41164

Published Nov 17, 2021

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins us…

CVSS 8.2 · High

CVE-2021-32809

Published Aug 12, 2021

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/c…

CVSS 4.6 · Medium

CVE-2021-21391

Published Apr 29, 2021

CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-…

CVSS 6.5 · Medium

CVE-2021-21254

Published Jan 29, 2021

CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ckeditor/ckeditor5-markdown-gfm) before version 25.0.0 has a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26272

Published Jan 26, 2021

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (…

CVSS 6.5 · Medium

CVE-2021-26271

Published Jan 26, 2021

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advance…

CVSS 6.5 · Medium

CVE-2020-27193

Published Nov 12, 2020

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and p…

CVSS 6.1 · Medium

CVE-2020-9281

Published Mar 7, 2020

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protec…

CVSS 6.1 · Medium
Showing 1-25 of 34 CVEsPage 1 of 2