VYPR
Medium severity6.1NVD Advisory· Published Mar 10, 2020· Updated Jun 17, 2026

CVE-2020-9440

CVE-2020-9440

Description

A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • cpe:2.3:a:ckeditor:ckeditor:4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:webspellchecker:webspellchecker:*:*:*:*:*:*:*:*
    Range: <=5.5.7.5
  • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • CKEditor/CKEditordescription
  • Range: <=5.5.7.5

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.