Medium severity6.1NVD Advisory· Published Nov 14, 2018· Updated Jun 17, 2026
CVE-2018-17960
CVE-2018-17960
Description
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ckeditornpm | < 4.11.0 | 4.11.0 |
typo3/cms-corePackagist | >= 8.0.0, < 8.7.21 | 8.7.21 |
typo3/cms-corePackagist | >= 9.0.0, < 9.5.2 | 9.5.2 |
typo3/cmsPackagist | >= 8.0.0, < 8.7.21 | 8.7.21 |
typo3/cmsPackagist | >= 9.0.0, < 9.5.2 | 9.5.2 |
Affected products
4- ghsa-coords3 versions
>= 8.0.0, < 8.7.21+ 2 more
- (no CPE)range: >= 8.0.0, < 8.7.21
- (no CPE)range: >= 8.0.0, < 8.7.21
- (no CPE)range: < 4.11.0
Patches
Vulnerability mechanics
References
11- ckeditor.com/blog/CKEditor-4.11-with-emoji-dropdown-and-auto-link-on-typing-released/nvdExploitVendor Advisory
- ckeditor.com/cke4/release/CKEditor-4.11.0nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-g68x-vvqq-pvw3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-17960ghsaADVISORY
- ckeditor.com/blog/CKEditor-4.11-with-emoji-dropdown-and-auto-link-on-typing-releasedghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2018-17960.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2018-17960.yamlghsaWEB
- typo3.org/security/advisory/typo3-core-sa-2018-005ghsaWEB
- web.archive.org/web/20200227030123/http://www.securityfocus.com/bid/109205ghsaWEB
- www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlnvdWEB
- www.securityfocus.com/bid/109205nvd
News mentions
0No linked articles in our index yet.