Skip to content
Noroxi

ckeditor records

34 published records for vendor ckeditor.

All records

34 records
  • A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine,

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    ckeditor · ckeditorJun 13, 2023

  • Regular expression Denial of Service in dialog plugin

    HighCVSS 7.5No exploitEPSS 2%

    ckeditor · ckeditorMar 16, 2022

  • CVE-2011-4972
    31Monitor

    hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attacke

    HighCVSS 7.5No exploitEPSS 2%

    ckeditor · ckeditorNov 13, 2019

  • It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the

    MediumCVSS 6.5No exploitEPSS 2%

    ckeditor · ckeditorJan 26, 2021

  • It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles in

    MediumCVSS 6.5No exploitEPSS 2%

    ckeditor · ckeditorJan 26, 2021

  • Regular expression Denial of Service in Markdown plugin

    MediumCVSS 6.5No exploitEPSS 2%

    ckeditor · ckeditor5Jan 29, 2021

  • Regular expression Denial of Service in multiple packages

    MediumCVSS 6.5No exploitEPSS 2%

    ckeditor · ckeditor5-engineApr 28, 2021

  • CVE-2012-2067
    27Monitor

    Unspecified vulnerability in the CKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.

    MediumCVSS 6.8No exploitEPSS 2%

    ckeditor · fckeditorSep 4, 2012

  • CVE-2020-9281
    25Monitor

    A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitra

    MediumCVSS 6.1No exploitEPSS 4%

    ckeditor · ckeditorMar 6, 2020

  • A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attack

    MediumCVSS 6.1Proof of conceptEPSS 3%

    ckeditor · ckeditorJun 9, 2021

  • CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget.

    MediumCVSS 6.1Proof of conceptEPSS 2%

    ckeditor · ckeditorFeb 13, 2023

  • A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web scrip

    MediumCVSS 6.1No exploitEPSS 2%

    ckeditor · ckeditorNov 12, 2020

  • CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.

    MediumCVSS 6.1No exploitEPSS 2%

    ckeditor · ckeditorNov 14, 2018

  • CVE-2018-9861
    25Monitor

    Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in

    MediumCVSS 6.1No exploitEPSS 2%

    ckeditor · enhanced imageApr 19, 2018

  • Cross-site scripting (XSS) vulnerability in samples with enabled the preview feature

    MediumCVSS 6.1Proof of conceptEPSS 2%

    ckeditor · ckeditorFeb 7, 2024

  • CVE-2020-9440
    24Monitor

    A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web scr

    MediumCVSS 6.1No exploitEPSS 1%

    ckeditor · ckeditorMar 10, 2020

  • Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web sc

    MediumCVSS 6.1No exploitEPSS 1%

    ckeditor · ckeditor 5-linkMay 22, 2018

  • ckeditor4 plugins vulnerable to cross-site scripting caused by the editor instance destroying process

    MediumCVSS 6.1No exploitEPSS 1%

    ckeditor · ckeditorMar 22, 2023

  • CKEditor4 Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detection

    MediumCVSS 6.1No exploitEPSS 1%

    ckeditor · ckeditorFeb 7, 2024

  • Code Snippet GeSHi plugin has reflected cross-site scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    ckeditor · ckeditorAug 21, 2024

  • CKEditor: Cross-site scripting (XSS) in the HTML Support package

    MediumCVSS 6.1No exploitEPSS 0%

    ckeditor · ckeditor5Mar 5, 2026

  • HTML comments vulnerability allowing to execute JavaScript code

    MediumCVSS 5.4No exploitEPSS 2%

    ckeditor · ckeditorNov 17, 2021

  • Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML

    MediumCVSS 5.4No exploitEPSS 1%

    ckeditor · ckeditorNov 17, 2021

  • Execution of JavaScript code using malformed HTML in ckeditor

    MediumCVSS 5.4No exploitEPSS 1%

    ckeditor · ckeditorAug 12, 2021

  • Cross-site Scripting in CKEditor4

    MediumCVSS 5.4No exploitEPSS 1%

    ckeditor · ckeditorMar 16, 2022