Medium severity6.1NVD Advisory· Published May 22, 2018· Updated Jun 17, 2026
CVE-2018-11093
CVE-2018-11093
Description
Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@ckeditor/ckeditor5-linknpm | >= 0.3.0, < 10.0.1 | 10.0.1 |
Affected products
2Patches
Vulnerability mechanics
References
8- ckeditor.com/blog/CKEditor-5-v10.0.1-released/nvdRelease NotesVendor Advisory
- github.com/advisories/GHSA-gvpx-9459-w3mjghsaADVISORY
- github.com/ckeditor/ckeditor5-link/blob/master/CHANGELOG.mdnvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-11093ghsaADVISORY
- ckeditor.com/blog/CKEditor-5-v10.0.1-releasedghsaWEB
- github.com/ckeditor/ckeditor5-link/commit/8cb782eceba10fc481e4021cb5d25b2a85d1b04eghsaWEB
- snyk.io/vuln/SNYK-JS-CKEDITORCKEDITOR5LINK-72892ghsaWEB
- www.npmjs.com/advisories/1154ghsaWEB
News mentions
0No linked articles in our index yet.