Medium severity6.1NVD Advisory· Published Apr 19, 2018· Updated Jun 17, 2026
CVE-2018-9861
CVE-2018-9861
Description
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
drupal/corePackagist | >= 8.5.0, < 8.5.2 | 8.5.2 |
ckeditor-devnpm | >= 4.5.10, < 4.9.2 | 4.9.2 |
drupal/corePackagist | >= 8.0, < 8.4.7 | 8.4.7 |
drupal/drupalPackagist | >= 8.0, < 8.4.7 | 8.4.7 |
drupal/drupalPackagist | >= 8.5, < 8.5.2 | 8.5.2 |
Affected products
5- cpe:2.3:a:ckeditor:enhanced_image:*:*:*:*:*:ckeditor:*:*Range: >=4.5.10,<4.9.2
- ghsa-coords3 versions
>= 8.5.0, < 8.5.2+ 2 more
- (no CPE)range: >= 8.5.0, < 8.5.2
- (no CPE)range: >= 8.0, < 8.4.7
- (no CPE)range: >= 4.5.10, < 4.9.2
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-g78h-pf65-46rvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-9861ghsaADVISORY
- www.drupal.org/sa-core-2018-003nvdThird Party AdvisoryWEB
- www.securityfocus.com/bid/103924nvdWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2018-9861.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2018-9861.yamlghsaWEB
- github.com/ckeditor/ckeditor-dev/blob/master/CHANGES.mdnvdRelease NotesWEB
- www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlnvdWEB
News mentions
0No linked articles in our index yet.