VYPR

Ckeditor Plugin Openlink

by Mlewand

Source repositories

CVEs (2)

  • CVE-2024-37888Jun 14, 2024
    risk 0.02cvss epss 0.01

    The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute JavaScript code by abusing link href attribute. It affects all users using the Open Link plugin at version < **1.0.5**.

  • CVE-2024-45400Sep 5, 2024
    risk 0.00cvss epss 0.00

    ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possibility to open a link in a new tab. A vulnerability in versions of the plugin prior to 1.0.7 allowed a user to execute JavaScript code by abusing the link href…