VYPR
Medium severity6.1NVD Advisory· Published May 22, 2018· Updated Jun 17, 2026

CVE-2018-11093

CVE-2018-11093

Description

Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@ckeditor/ckeditor5-linknpm
>= 0.3.0, < 10.0.110.0.1

Affected products

2

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.