<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – CKEditor</title>
  <link>https://cvedaily.com/pages/tags/ckeditor.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ckeditor.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – CKEditor</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-41524 – Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41524</guid>
    <pubDate>Fri, 08 May 2026 15:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41524</strong></p>
  <p>Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with Laravel Blade's unescaped output directive {!! !!}. Any JavaScript or HTML injected by an editor-role user is permanently stored and executed in every visitor's browser upon page load. This issue has…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35164 – Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35164</guid>
    <pubDate>Mon, 06 Apr 2026 18:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35164</strong></p>
  <p>Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found in app/Http/Controllers/Dashboard/CkEditorController.php within the ckupload method. The method fails to validate uploaded file types and relies entirely on user input. This allows an authenticated user to upload executable PHP scripts and gain Remote…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35047 – Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35047</guid>
    <pubDate>Mon, 06 Apr 2026 18:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35047</strong></p>
  <p>Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitrary files, including executable scripts. This may lead to Remote Code Execution (RCE) on the server, potentially resulting in full system compromise, data exfiltration, or service disruption. All users running affected versions of BraveCMS are impact…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28343 – CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Sta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28343</guid>
    <pubDate>Thu, 05 Mar 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28343</strong></p>
  <p>CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13980 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13980</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13980</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before 1.5.1, from 1.6.0 before 1.6.4.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61261 – A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 &amp; Angul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61261</guid>
    <pubDate>Fri, 07 Nov 2025 19:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61261</strong></p>
  <p>A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59547 – DNN (formerly DotNetNuke) is an open-source web content management platform (CMS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59547</guid>
    <pubDate>Tue, 23 Sep 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59547</strong></p>
  <p>DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the CKEditor file upload endpoint has insufficient sanitization for filenames allowing probing network endpoints. A specially crafted request can be made to upload a file with Unicode characters, which would be translated into a path that could expose resources in…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-176</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55727 – XWiki Remote Macros provides XWiki rendering macros that are useful when migrati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55727</guid>
    <pubDate>Tue, 09 Sep 2025 19:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55727</strong></p>
  <p>XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the width parameter in the column macro allows remote code execution for any user who can edit any page or who can access the CKEditor converter. The width parameter is used without escaping in XWiki syntax, thus allow…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-58064 – CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. cke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58064</guid>
    <pubDate>Thu, 04 Sep 2025 10:42:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-58064</strong></p>
  <p>CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 44.2.0 through 45.2.1 contain a Cross-Site Scripting (XSS) vulnerability. Ability to exploit could be triggered by a specific user action (leading to unauthorized JavaScript code execution) if the attacker managed to insert a malicious content into the…</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-43761 – A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43761</guid>
    <pubDate>Fri, 22 Aug 2025 21:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-43761</strong></p>
  <p>A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.4, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the frontend-editor-ckeditor-web/ckeditor/samples/old/ajax.html pa…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-9103 – A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9103</guid>
    <pubDate>Mon, 18 Aug 2025 04:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-9103</strong></p>
  <p>A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is an unknown functionality of the component CKEditor. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor declares this as "intended behavior…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-10054 – An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-10054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-10054</guid>
    <pubDate>Mon, 04 Aug 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-10054</strong></p>
  <p>An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitrary file upload vulnerability in its File Manager plugin. The upload handler located at adm/ui/js/ckeditor/plugins/pgrfilemanager/php/upload.php fails to properly validate file extensions, allowing attackers to upload files with misleading extensions…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-10054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31487 – The XWiki JIRA extension provides various integration points between XWiki and J...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31487</guid>
    <pubDate>Thu, 03 Apr 2025 19:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31487</strong></p>
  <p>The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, any logged in XWiki user could edit his/her user profile wiki page and use that JIRA macro, specifying a fake JIRA URL that returns an XML specifying a DOCTYPE pointing to a local file on the XWiki server host and displaying that file's content in one…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2978 – A vulnerability was found in WCMS 11. It has been rated as critical. Affected by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2978</guid>
    <pubDate>Mon, 31 Mar 2025 06:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2978</strong></p>
  <p>A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?articleadmin/upload/?&CKEditor=container&CKEditorFuncNum=1 of the component Article Publishing Page. The manipulation of the argument Upload leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public a…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-25299 – CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Dur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25299</guid>
    <pubDate>Thu, 20 Feb 2025 20:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-25299</strong></p>
  <p>CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. During a recent internal audit, a Cross-Site Scripting (XSS) vulnerability was discovered in the CKEditor 5 real-time collaboration package. This vulnerability affects user markers, which represent users' positions within the document. It can lead to unauthorized JavaScript code execution, which might happen with a very…</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25062 – An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25062</guid>
    <pubDate>Mon, 03 Feb 2025 04:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25062</strong></p>
  <p>An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaScript that may be executed when an administrator attempts to edit a piece of content. This vulnerability is mitigated by the fact that an attack…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-23025 – XWiki Platform is a generic wiki platform offering runtime services for applicat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23025</guid>
    <pubDate>Tue, 14 Jan 2025 18:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-23025</strong></p>
  <p>XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension was **experimental**, and thus **not recommended**, in the versions affected by this vulnerability. It has become enabled by default, and thus recommended, starting with XWiki 16.9.0. A user with only **edit right** can join a realtime editing sessio…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13245 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13245</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13245</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-56363 – APTRS (Automated Penetration Testing Reporting System) is a Python and Django-ba...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56363</guid>
    <pubDate>Mon, 23 Dec 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-56363</strong></p>
  <p>APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. In 1.0, there is a vulnerability in the web application's handling of user-supplied input that is incorporated into a Jinja2 template. Specifically, when user input is improperly sanitized or validated, an attacker can inject Jin…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-97</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45613 – CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45613</guid>
    <pubDate>Wed, 25 Sep 2024 14:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45613</strong></p>
  <p>CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen w…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45400 – ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45400</guid>
    <pubDate>Fri, 06 Sep 2024 00:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45400</strong></p>
  <p>ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possibility to open a link in a new tab. A vulnerability in versions of the plugin prior to 1.0.7 allowed a user to execute JavaScript code by abusing the link href attribute. The fix is available starting with version 1.0.7.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-43411 – CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoreti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43411</guid>
    <pubDate>Wed, 21 Aug 2024 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-43411</strong></p>
  <p>CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. The issue impacts only editor instances with enabled version notifications. Plea…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43407 – CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43407</guid>
    <pubDate>Wed, 21 Aug 2024 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43407</strong></p>
  <p>CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in CKEditor 4 Code Snippet GeSHi plugin. The vulnerability allowed a reflected XSS attack by exploiting a flaw in the GeSHi syntax highlighter library hosted by the victim. The GeSHi library was included as a vendor dependency in CKEditor 4 source files. In a specific scenario, an a…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-42489 – Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42489</guid>
    <pubDate>Mon, 12 Aug 2024 16:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-42489</strong></p>
  <p>Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind of attack. This vulnerability is fixed in 1.10.1.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7329 – A vulnerability, which was classified as critical, was found in YouDianCMS 7. Af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7329</guid>
    <pubDate>Wed, 31 Jul 2024 23:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7329</strong></p>
  <p>A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the file /Public/ckeditor/plugins/multiimage/dialogs/image_upload.php. The manipulation of the argument files leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability i…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37888 – The Open Link is a CKEditor plugin, extending context menu with a possibility to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37888</guid>
    <pubDate>Fri, 14 Jun 2024 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37888</strong></p>
  <p>The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute JavaScript code by abusing link href attribute. It affects all users using the Open Link plugin at version < **1.0.5**.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-30162 – Invision Community through 4.7.16 allows remote code execution via the applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30162</guid>
    <pubDate>Fri, 07 Jun 2024 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-30162</strong></p>
  <p>Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugins/ directory without properly verifying their content. This can be exploited by admin users (with…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46694 – Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46694</guid>
    <pubDate>Tue, 28 May 2024 20:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46694</strong></p>
  <p>Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-24816 – CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-si...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24816</guid>
    <pubDate>Wed, 07 Feb 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-24816</strong></p>
  <p>CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior to 4.24.0-lts in samples that use the `preview` feature. All integrators that use these samples in the production code can be affected. The vulnerability allows an attacker to execute JavaScript code by abusing the misconfigured preview fea…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2018-25094 – A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25094</guid>
    <pubDate>Sun, 03 Dec 2023 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2018-25094</strong></p>
  <p>A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4.0 and classified as problematic. This issue affects some unknown processing of the file ckeditor/filemanager/browser/default/image.php. The manipulation of the argument fid with the input ../../../etc/passwd leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. Upgrading…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-24</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4771 – A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4771</guid>
    <pubDate>Thu, 16 Nov 2023 14:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4771</strong></p>
  <p>A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-37905 – ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37905</guid>
    <pubDate>Fri, 21 Jul 2023 20:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-37905</strong></p>
  <p>ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the `ckeditor-wordcount-plugin` plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. This issue has been addressed in version 1.17.12 of the `ckeditor-wordcount-plugin` plugin and users are advised to upgrade. There are no known workarounds for this…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-36477 – XWiki Platform is a generic wiki platform offering runtime services for applicat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36477</guid>
    <pubDate>Fri, 30 Jun 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-36477</strong></p>
  <p>XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights can edit all pages in the `CKEditor' space. This makes it possible to perform a variety of harmful actions, such as removing technical documents, leading to loss of service and editing the javascript configuration of CKEditor, leading to persistent XSS. This issue has…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-31541 – A unrestricted file upload vulnerability was discovered in the ‘Browse and uploa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31541</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31541</guid>
    <pubDate>Tue, 13 Jun 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-31541</strong></p>
  <p>A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31541">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-29209 – XWiki Commons are technical libraries common to several other top level XWiki pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29209</guid>
    <pubDate>Sat, 15 Apr 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-29209</strong></p>
  <p>XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the macro parameters of the legacy notification act…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-48110 – CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48110</guid>
    <pubDate>Mon, 13 Feb 2023 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-48110</strong></p>
  <p>CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation discusses that it is the responsibility of an integrator (who is adding CKEditor 5 functionality to a website) to choose the correct security settings for their use case…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-22457 – CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22457</guid>
    <pubDate>Wed, 04 Jan 2023 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-22457</strong></p>
  <p>CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros with the rights of the current user. If a privileged user with programming rights was tricked into executing a GET request to this document with certain parameters (e.g.…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39950 – An improper neutralization of input during web page generation vulnerability [CW...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39950</guid>
    <pubDate>Wed, 02 Nov 2022 12:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39950</strong></p>
  <p>An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described in CVE-2020-9281.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-42116 – A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42116</guid>
    <pubDate>Tue, 18 Oct 2022 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-42116</strong></p>
  <p>A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31175 – CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31175</guid>
    <pubDate>Wed, 03 Aug 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31175</strong></p>
  <p>CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript code after fulfilling special conditions. The affected packages are `@ckeditor/ckeditor5-markdown-gfm`, `@ckeditor/ckeditor5-html-support`, and `@ckeditor/ckeditor5-html-e…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24728 – CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24728</guid>
    <pubDate>Wed, 16 Mar 2022 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24728</strong></p>
  <p>CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0.…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-24977 – ImpressCMS before 1.4.2 allows unauthenticated remote code execution via .....//...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24977</guid>
    <pubDate>Mon, 14 Feb 2022 12:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-24977</strong></p>
  <p>ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP installation supports upload_progress.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13669 – Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13669</guid>
    <pubDate>Fri, 11 Feb 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13669</strong></p>
  <p>Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10.; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41165 – CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41165</guid>
    <pubDate>Wed, 17 Nov 2021 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41165</strong></p>
  <p>CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The prob…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41164 – CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41164</guid>
    <pubDate>Wed, 17 Nov 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41164</strong></p>
  <p>CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The pro…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-36493 – DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36493</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36493</guid>
    <pubDate>Fri, 22 Oct 2021 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-36493</strong></p>
  <p>DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36493">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-36492 – DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36492</guid>
    <pubDate>Fri, 22 Oct 2021 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-36492</strong></p>
  <p>DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component select_media.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-36491 – DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36491</guid>
    <pubDate>Fri, 22 Oct 2021 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-36491</strong></p>
  <p>DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-36490 – DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36490</guid>
    <pubDate>Fri, 22 Oct 2021 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-36490</strong></p>
  <p>DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-23044 – DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-23044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-23044</guid>
    <pubDate>Fri, 22 Oct 2021 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-23044</strong></p>
  <p>DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-23044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37695 – ckeditor is an open source WYSIWYG HTML editor with rich content support. A pote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37695</guid>
    <pubDate>Fri, 13 Aug 2021 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37695</strong></p>
  <p>ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32809 – ckeditor is an open source WYSIWYG HTML editor with rich content support. A pote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32809</guid>
    <pubDate>Thu, 12 Aug 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32809</strong></p>
  <p>ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed abo…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32808 – ckeditor is an open source WYSIWYG HTML editor with rich content support. A vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32808</guid>
    <pubDate>Thu, 12 Aug 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32808</strong></p>
  <p>ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0.…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-36389 – In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36389</guid>
    <pubDate>Thu, 17 Jun 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-36389</strong></p>
  <p>In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-33829 – A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEdito...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33829</guid>
    <pubDate>Wed, 09 Jun 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-33829</strong></p>
  <p>A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21391 – CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21391</guid>
    <pubDate>Thu, 29 Apr 2021 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21391</strong></p>
  <p>CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-gfm, ckeditor5-media-embed, ckeditor5-paste-from-office, and ckeditor5-widget. Following an internal audit, a regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21254 – CKEditor 5 is an open source rich text editor framework with a modular architect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21254</guid>
    <pubDate>Fri, 29 Jan 2021 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21254</strong></p>
  <p>CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ckeditor/ckeditor5-markdown-gfm) before version 25.0.0 has a regex denial of service (ReDoS) vulnerability. The vulnerability allowed to abuse link recognition regular expression, which could cause a significant performance drop resulting in browser tab freeze. It affects all user…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-26272 – It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26272</guid>
    <pubDate>Tue, 26 Jan 2021 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-26272</strong></p>
  <p>It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-26271 – It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26271</guid>
    <pubDate>Tue, 26 Jan 2021 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-26271</strong></p>
  <p>It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-27193 – A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEdit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27193</guid>
    <pubDate>Thu, 12 Nov 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-27193</strong></p>
  <p>A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-9440 – A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9440</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9440</guid>
    <pubDate>Tue, 10 Mar 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-9440</strong></p>
  <p>A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9440">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-9281 – A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEdit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9281</guid>
    <pubDate>Sat, 07 Mar 2020 01:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-9281</strong></p>
  <p>A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-19502 – Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19502</guid>
    <pubDate>Mon, 02 Dec 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-19502</strong></p>
  <p>Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19502">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4972 – hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4972</guid>
    <pubDate>Wed, 13 Nov 2019 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4972</strong></p>
  <p>hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-9349 – The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-9349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-9349</guid>
    <pubDate>Tue, 27 Aug 2019 12:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-9349</strong></p>
  <p>The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-9349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-9870 – plugin.js in the w8tcha oEmbed plugin before 2019-03-14 for CKEditor mishandles ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9870</guid>
    <pubDate>Thu, 21 Mar 2019 16:01:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-9870</strong></p>
  <p>plugin.js in the w8tcha oEmbed plugin before 2019-03-14 for CKEditor mishandles SCRIPT elements.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-19</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-17960 – CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode past...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17960</guid>
    <pubDate>Wed, 14 Nov 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-17960</strong></p>
  <p>CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-11093 – Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11093</guid>
    <pubDate>Tue, 22 May 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-11093</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-9861 – Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-9861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-9861</guid>
    <pubDate>Thu, 19 Apr 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-9861</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-9861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9182 – Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9182</guid>
    <pubDate>Fri, 04 Nov 2016 10:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9182</strong></p>
  <p>Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user permission. But, the method name in PHP reflection is case insensitive, and Exponent CMS permits undefined actions to execute by default, so an attacker can use a capitalized method name to bypass the permission check, e.g., controller=expHTMLEditor&action=preview&editor=ckedit…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-5191 – Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-5191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-5191</guid>
    <pubDate>Thu, 07 Aug 2014 11:13:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-5191</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-5191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-2067 – Unspecified vulnerability in the CKeditor module 6.x-2.x before 6.x-2.3 and the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2067</guid>
    <pubDate>Wed, 05 Sep 2012 00:55:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-2067</strong></p>
  <p>Unspecified vulnerability in the CKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.7 for Drupal, when the core PHP module is enabled, allows remote authenticated users or remote attackers to execute arbitrary PHP code via the text parameter to a text filter.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-2066 – Cross-site scripting (XSS) vulnerability in the FCKeditor module 6.x-2.x before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2066</guid>
    <pubDate>Wed, 05 Sep 2012 00:55:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-2066</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the FCKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.7 for Drupal allows remote authenticated users or remote attackers to inject arbitrary web script or HTML via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-2722 – The node selection interface in the WYSIWYG editor (CKEditor) in the Node Embed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2722</guid>
    <pubDate>Wed, 27 Jun 2012 00:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-2722</strong></p>
  <p>The node selection interface in the WYSIWYG editor (CKEditor) in the Node Embed module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.0 for Drupal does not properly check permissions, which allows remote attackers to bypass intended access restrictions and read node titles.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2722">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
