VYPR
Medium severity5.4NVD Advisory· Published Mar 16, 2022· Updated Jun 17, 2026

CVE-2022-24728

CVE-2022-24728

Description

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ckeditor4npm
< 4.18.04.18.0

Affected products

20
  • cpe:2.3:a:ckeditor:ckeditor:*:*:*:*:*:*:*:*
    Range: >=4.0,<4.18.0
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
    Range: >=8.0.0,<9.2.15
  • cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:*
    Range: <22.1.1
  • cpe:2.3:a:oracle:commerce_merchandising:11.3.2:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*range: >=8.0.7.0.0,<=8.1.0.0.0
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.1:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:financial_services_behavior_detection_platform:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:oracle:financial_services_behavior_detection_platform:*:*:*:*:*:*:*:*range: >=8.1.1.0,<=8.1.2.1
    • cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.0.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.0.8.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:financial_services_trade-based_anti_money_laundering:8.0.7:*:*:*:enterprise:*:*:*+ 1 more
    • cpe:2.3:a:oracle:financial_services_trade-based_anti_money_laundering:8.0.7:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:oracle:financial_services_trade-based_anti_money_laundering:8.0.8:*:*:*:enterprise:*:*:*
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
  • osv-coords2 versions
    >= 8.0.0, < 9.2.15+ 1 more
    • (no CPE)range: >= 8.0.0, < 9.2.15
    • (no CPE)range: < 4.18.0
  • Range: < 4.18.0

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.