Medium severity6.1NVD Advisory· Published Nov 12, 2020· Updated Jun 17, 2026
CVE-2020-27193
CVE-2020-27193
Description
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ckeditor4npm | < 4.15.1 | 4.15.1 |
Affected products
25cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:*Range: <21.1.0.00.01
- cpe:2.3:a:oracle:banking_party_management:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_platform:2.4.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:oracle:banking_platform:2.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_platform:2.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_platform:2.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_merchandising:11.0.0:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:oracle:commerce_merchandising:11.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:commerce_merchandising:11.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:commerce_merchandising:11.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:commerce_merchandising:11.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:commerce_merchandising:11.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:commerce_merchandising:11.3.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*range: >=8.0.6,<=8.0.9
- cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*Range: <9.2.6.0
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
- CKEditor/CKEditordescription
Patches
Vulnerability mechanics
References
10- www.oracle.com//security-alerts/cpujul2021.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuApr2021.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuoct2021.htmlnvdPatchThird Party AdvisoryWEB
- ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released/nvdRelease NotesVendor Advisory
- ckeditor.com/cke4/release/CKEditor-4.15.1nvdRelease NotesVendor AdvisoryWEB
- ckeditor.com/ckeditor-4/download/nvdRelease NotesVendor Advisory
- github.com/advisories/GHSA-4m44-5j2g-xf64ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-27193ghsaADVISORY
- ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-releasedghsaWEB
- ckeditor.com/ckeditor-4/downloadghsaWEB
News mentions
0No linked articles in our index yet.