ckeditor records
34 published records for vendor ckeditor.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 76.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')25
- CWE-400 Uncontrolled Resource Consumption3
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
34 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-31541Proof of concept | A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine,ckeditor · ckeditor · CWE-434 | Critical9.8 | — | 1.4% | Jun 13, 2023 |
31Monitor | CVE-2022-24729No exploit | Regular expression Denial of Service in dialog pluginckeditor · ckeditor · CWE-400 | High7.5 | — | 2.5% | Mar 16, 2022 |
31Monitor | CVE-2011-4972No exploit | hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackeckeditor · ckeditor · CWE-200 | High7.5 | — | 1.7% | Nov 13, 2019 |
27Monitor | CVE-2021-26272No exploit | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the ckeditor · ckeditor · CWE-829 | Medium6.5 | — | 2.2% | Jan 26, 2021 |
27Monitor | CVE-2021-26271No exploit | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles inckeditor · ckeditor · CWE-829 | Medium6.5 | — | 2.0% | Jan 26, 2021 |
27Monitor | CVE-2021-21254No exploit | Regular expression Denial of Service in Markdown pluginckeditor · ckeditor5 · CWE-400 | Medium6.5 | — | 1.8% | Jan 29, 2021 |
27Monitor | CVE-2021-21391No exploit | Regular expression Denial of Service in multiple packagesckeditor · ckeditor5-engine · CWE-400 | Medium6.5 | — | 1.7% | Apr 28, 2021 |
27Monitor | CVE-2012-2067No exploit | Unspecified vulnerability in the CKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.ckeditor · fckeditor | Medium6.8 | — | 1.5% | Sep 4, 2012 |
25Monitor | CVE-2020-9281No exploit | A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrackeditor · ckeditor · CWE-79 | Medium6.1 | — | 4.3% | Mar 6, 2020 |
25Monitor | CVE-2021-33829Proof of concept | A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackckeditor · ckeditor · CWE-79 | Medium6.1 | — | 3.2% | Jun 9, 2021 |
25Monitor | CVE-2022-48110Proof of concept | CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget.ckeditor · ckeditor · CWE-79 | Medium6.1 | — | 2.1% | Feb 13, 2023 |
25Monitor | CVE-2020-27193No exploit | A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web scripckeditor · ckeditor · CWE-79 | Medium6.1 | — | 2.0% | Nov 12, 2020 |
25Monitor | CVE-2018-17960No exploit | CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.ckeditor · ckeditor · CWE-79 | Medium6.1 | — | 1.9% | Nov 14, 2018 |
25Monitor | CVE-2018-9861No exploit | Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in ckeditor · enhanced image · CWE-79 | Medium6.1 | — | 1.7% | Apr 19, 2018 |
24Monitor | CVE-2024-24816Proof of concept | Cross-site scripting (XSS) vulnerability in samples with enabled the preview featureckeditor · ckeditor · CWE-79 | Medium6.1 | — | 1.7% | Feb 7, 2024 |
24Monitor | CVE-2020-9440No exploit | A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web scrckeditor · ckeditor · CWE-79 | Medium6.1 | — | 1.3% | Mar 10, 2020 |
24Monitor | CVE-2018-11093No exploit | Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web scckeditor · ckeditor 5-link · CWE-79 | Medium6.1 | — | 1.0% | May 22, 2018 |
24Monitor | CVE-2023-28439No exploit | ckeditor4 plugins vulnerable to cross-site scripting caused by the editor instance destroying processckeditor · ckeditor · CWE-79 | Medium6.1 | — | 0.7% | Mar 22, 2023 |
24Monitor | CVE-2024-24815No exploit | CKEditor4 Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detectionckeditor · ckeditor · CWE-79 | Medium6.1 | — | 0.7% | Feb 7, 2024 |
24Monitor | CVE-2024-43407No exploit | Code Snippet GeSHi plugin has reflected cross-site scripting (XSS) vulnerabilityckeditor · ckeditor · CWE-79 | Medium6.1 | — | 0.5% | Aug 21, 2024 |
24Monitor | CVE-2026-28343No exploit | CKEditor: Cross-site scripting (XSS) in the HTML Support packageckeditor · ckeditor5 · CWE-79 | Medium6.1 | — | 0.3% | Mar 5, 2026 |
21Monitor | CVE-2021-41165No exploit | HTML comments vulnerability allowing to execute JavaScript codeckeditor · ckeditor · CWE-79 | Medium5.4 | — | 1.6% | Nov 17, 2021 |
21Monitor | CVE-2021-41164No exploit | Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTMLckeditor · ckeditor · CWE-79 | Medium5.4 | — | 1.3% | Nov 17, 2021 |
21Monitor | CVE-2021-37695No exploit | Execution of JavaScript code using malformed HTML in ckeditorckeditor · ckeditor · CWE-79 | Medium5.4 | — | 1.3% | Aug 12, 2021 |
21Monitor | CVE-2022-24728No exploit | Cross-site Scripting in CKEditor4ckeditor · ckeditor · CWE-79 | Medium5.4 | — | 1.2% | Mar 16, 2022 |
- CVE-2023-3154139Monitor
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine,
CriticalCVSS 9.8Proof of conceptEPSS 1%ckeditor · ckeditorJun 13, 2023
- CVE-2022-2472931Monitor
Regular expression Denial of Service in dialog plugin
HighCVSS 7.5No exploitEPSS 2%ckeditor · ckeditorMar 16, 2022
- CVE-2011-497231Monitor
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attacke
HighCVSS 7.5No exploitEPSS 2%ckeditor · ckeditorNov 13, 2019
- CVE-2021-2627227Monitor
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the
MediumCVSS 6.5No exploitEPSS 2%ckeditor · ckeditorJan 26, 2021
- CVE-2021-2627127Monitor
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles in
MediumCVSS 6.5No exploitEPSS 2%ckeditor · ckeditorJan 26, 2021
- CVE-2021-2125427Monitor
Regular expression Denial of Service in Markdown plugin
MediumCVSS 6.5No exploitEPSS 2%ckeditor · ckeditor5Jan 29, 2021
- CVE-2021-2139127Monitor
Regular expression Denial of Service in multiple packages
MediumCVSS 6.5No exploitEPSS 2%ckeditor · ckeditor5-engineApr 28, 2021
- CVE-2012-206727Monitor
Unspecified vulnerability in the CKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.
MediumCVSS 6.8No exploitEPSS 2%ckeditor · fckeditorSep 4, 2012
- CVE-2020-928125Monitor
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitra
MediumCVSS 6.1No exploitEPSS 4%ckeditor · ckeditorMar 6, 2020
- CVE-2021-3382925Monitor
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attack
MediumCVSS 6.1Proof of conceptEPSS 3%ckeditor · ckeditorJun 9, 2021
- CVE-2022-4811025Monitor
CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget.
MediumCVSS 6.1Proof of conceptEPSS 2%ckeditor · ckeditorFeb 13, 2023
- CVE-2020-2719325Monitor
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web scrip
MediumCVSS 6.1No exploitEPSS 2%ckeditor · ckeditorNov 12, 2020
- CVE-2018-1796025Monitor
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
MediumCVSS 6.1No exploitEPSS 2%ckeditor · ckeditorNov 14, 2018
- CVE-2018-986125Monitor
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in
MediumCVSS 6.1No exploitEPSS 2%ckeditor · enhanced imageApr 19, 2018
- CVE-2024-2481624Monitor
Cross-site scripting (XSS) vulnerability in samples with enabled the preview feature
MediumCVSS 6.1Proof of conceptEPSS 2%ckeditor · ckeditorFeb 7, 2024
- CVE-2020-944024Monitor
A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web scr
MediumCVSS 6.1No exploitEPSS 1%ckeditor · ckeditorMar 10, 2020
- CVE-2018-1109324Monitor
Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web sc
MediumCVSS 6.1No exploitEPSS 1%ckeditor · ckeditor 5-linkMay 22, 2018
- CVE-2023-2843924Monitor
ckeditor4 plugins vulnerable to cross-site scripting caused by the editor instance destroying process
MediumCVSS 6.1No exploitEPSS 1%ckeditor · ckeditorMar 22, 2023
- CVE-2024-2481524Monitor
CKEditor4 Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detection
MediumCVSS 6.1No exploitEPSS 1%ckeditor · ckeditorFeb 7, 2024
- CVE-2024-4340724Monitor
Code Snippet GeSHi plugin has reflected cross-site scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%ckeditor · ckeditorAug 21, 2024
- CVE-2026-2834324Monitor
CKEditor: Cross-site scripting (XSS) in the HTML Support package
MediumCVSS 6.1No exploitEPSS 0%ckeditor · ckeditor5Mar 5, 2026
- CVE-2021-4116521Monitor
HTML comments vulnerability allowing to execute JavaScript code
MediumCVSS 5.4No exploitEPSS 2%ckeditor · ckeditorNov 17, 2021
- CVE-2021-4116421Monitor
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
MediumCVSS 5.4No exploitEPSS 1%ckeditor · ckeditorNov 17, 2021
- CVE-2021-3769521Monitor
Execution of JavaScript code using malformed HTML in ckeditor
MediumCVSS 5.4No exploitEPSS 1%ckeditor · ckeditorAug 12, 2021
- CVE-2022-2472821Monitor
Cross-site Scripting in CKEditor4
MediumCVSS 5.4No exploitEPSS 1%ckeditor · ckeditorMar 16, 2022