VYPR
Vendor

Fckeditor

Products
23
CVEs
54
Across products
78
Status
Private

Products

23

Recent CVEs

54
View all 54 CVEs →
  • CVE-2023-31541CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.

  • CVE-2021-41165HigNov 17, 2021
    risk 0.53cvss 8.2epss 0.01

    CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization,…

  • CVE-2021-41164HigNov 17, 2021
    risk 0.53cvss 8.2epss 0.01

    CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization,…

  • CVE-2021-32808HigAug 12, 2021
    risk 0.49cvss 7.6epss 0.01

    ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could…

  • CVE-2011-4972HigNov 13, 2019
    risk 0.49cvss 7.5epss 0.02

    hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.

  • CVE-2022-48110MedFeb 13, 2023
    risk 0.43cvss 6.1epss 0.02

    CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation discusses that it is the responsibility of an…

  • CVE-2022-24729MedMar 16, 2022
    risk 0.42cvss 6.5epss 0.02

    CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop…

  • CVE-2021-21391MedApr 29, 2021
    risk 0.42cvss 6.5epss 0.02

    CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-gfm, ckeditor5-media-embed, ckeditor5-paste-from-office, and ckeditor5-widget. Following an internal…

  • CVE-2021-21254MedJan 29, 2021
    risk 0.42cvss 6.5epss 0.02

    CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ckeditor/ckeditor5-markdown-gfm) before version 25.0.0 has a regex denial of service (ReDoS) vulnerability. The vulnerability allowed to abuse link recognition…

  • CVE-2021-26272MedJan 26, 2021
    risk 0.42cvss 6.5epss 0.02

    It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

  • CVE-2021-26271MedJan 26, 2021
    risk 0.42cvss 6.5epss 0.02

    It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

  • CVE-2021-37695HigAug 13, 2021
    risk 0.41cvss 7.3epss 0.01

    ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could…

  • CVE-2025-63830MedNov 14, 2025
    risk 0.40cvss 6.1epss 0.00

    CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

  • CVE-2024-37888MedJun 14, 2024
    risk 0.40cvss 6.1epss 0.01

    The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute JavaScript code by abusing link href attribute. It affects all users using the Open Link plugin at version < **1.0.5**.

  • CVE-2021-33829MedJun 9, 2021
    risk 0.40cvss 6.1epss 0.03

    A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.

  • CVE-2020-27193MedNov 12, 2020
    risk 0.40cvss 6.1epss 0.02

    A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

  • CVE-2020-9440MedMar 10, 2020
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.

  • CVE-2020-9281MedMar 7, 2020
    risk 0.40cvss 6.1epss 0.04

    A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

  • CVE-2018-17960MedNov 14, 2018
    risk 0.40cvss 6.1epss 0.02

    CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.

  • CVE-2018-9861MedApr 19, 2018
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script…