VYPR
Medium severity6.1NVD Advisory· Published Apr 19, 2018· Updated Jun 17, 2026

CVE-2018-9861

CVE-2018-9861

Description

Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
drupal/corePackagist
>= 8.5.0, < 8.5.28.5.2
ckeditor-devnpm
>= 4.5.10, < 4.9.24.9.2
drupal/corePackagist
>= 8.0, < 8.4.78.4.7
drupal/drupalPackagist
>= 8.0, < 8.4.78.4.7
drupal/drupalPackagist
>= 8.5, < 8.5.28.5.2

Affected products

5

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.