VYPR
Medium severity6.1NVD Advisory· Published Nov 14, 2018· Updated Jun 17, 2026

CVE-2018-17960

CVE-2018-17960

Description

CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ckeditornpm
< 4.11.04.11.0
typo3/cms-corePackagist
>= 8.0.0, < 8.7.218.7.21
typo3/cms-corePackagist
>= 9.0.0, < 9.5.29.5.2
typo3/cmsPackagist
>= 8.0.0, < 8.7.218.7.21
typo3/cmsPackagist
>= 9.0.0, < 9.5.29.5.2

Affected products

4

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.

CVE-2018-17960 · Medium · VYPR