VYPR
Medium severity6.1NVD Advisory· Published Nov 12, 2020· Updated Jun 17, 2026

CVE-2020-27193

CVE-2020-27193

Description

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ckeditor4npm
< 4.15.14.15.1

Affected products

25
  • cpe:2.3:a:ckeditor:ckeditor:4.15.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:*
    Range: <21.1.0.00.01
  • cpe:2.3:a:oracle:banking_party_management:2.7.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:banking_platform:2.4.0:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:oracle:banking_platform:2.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:banking_platform:2.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:banking_platform:2.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:commerce_merchandising:11.0.0:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:oracle:commerce_merchandising:11.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:commerce_merchandising:11.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:commerce_merchandising:11.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:commerce_merchandising:11.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:commerce_merchandising:11.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:commerce_merchandising:11.3.2:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*range: >=8.0.6,<=8.0.9
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
    Range: <9.2.6.0
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
  • CKEditor/CKEditordescription
  • ghsa-coords
    Range: < 4.15.1

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.