ckeditor kayıtları
ckeditor üreticisine ait 34 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %76,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')25
- CWE-400 Uncontrolled Resource Consumption3
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
34 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-31541Kavram kanıtı | A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine,ckeditor · ckeditor · CWE-434 | Kritik9,8 | — | %1,4 | 13 Haz 2023 |
31İzleyin | CVE-2022-24729İstismar yok | Regular expression Denial of Service in dialog pluginckeditor · ckeditor · CWE-400 | Yüksek7,5 | — | %2,5 | 16 Mar 2022 |
31İzleyin | CVE-2011-4972İstismar yok | hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackeckeditor · ckeditor · CWE-200 | Yüksek7,5 | — | %1,7 | 13 Kas 2019 |
27İzleyin | CVE-2021-26272İstismar yok | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the ckeditor · ckeditor · CWE-829 | Orta6,5 | — | %2,2 | 26 Oca 2021 |
27İzleyin | CVE-2021-26271İstismar yok | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles inckeditor · ckeditor · CWE-829 | Orta6,5 | — | %2,0 | 26 Oca 2021 |
27İzleyin | CVE-2021-21254İstismar yok | Regular expression Denial of Service in Markdown pluginckeditor · ckeditor5 · CWE-400 | Orta6,5 | — | %1,8 | 29 Oca 2021 |
27İzleyin | CVE-2021-21391İstismar yok | Regular expression Denial of Service in multiple packagesckeditor · ckeditor5-engine · CWE-400 | Orta6,5 | — | %1,7 | 28 Nis 2021 |
27İzleyin | CVE-2012-2067İstismar yok | Unspecified vulnerability in the CKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.ckeditor · fckeditor | Orta6,8 | — | %1,5 | 4 Eyl 2012 |
25İzleyin | CVE-2020-9281İstismar yok | A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrackeditor · ckeditor · CWE-79 | Orta6,1 | — | %4,3 | 6 Mar 2020 |
25İzleyin | CVE-2021-33829Kavram kanıtı | A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackckeditor · ckeditor · CWE-79 | Orta6,1 | — | %3,2 | 9 Haz 2021 |
25İzleyin | CVE-2022-48110Kavram kanıtı | CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget.ckeditor · ckeditor · CWE-79 | Orta6,1 | — | %2,1 | 13 Şub 2023 |
25İzleyin | CVE-2020-27193İstismar yok | A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web scripckeditor · ckeditor · CWE-79 | Orta6,1 | — | %2,0 | 12 Kas 2020 |
25İzleyin | CVE-2018-17960İstismar yok | CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.ckeditor · ckeditor · CWE-79 | Orta6,1 | — | %1,9 | 14 Kas 2018 |
25İzleyin | CVE-2018-9861İstismar yok | Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in ckeditor · enhanced image · CWE-79 | Orta6,1 | — | %1,7 | 19 Nis 2018 |
24İzleyin | CVE-2024-24816Kavram kanıtı | Cross-site scripting (XSS) vulnerability in samples with enabled the preview featureckeditor · ckeditor · CWE-79 | Orta6,1 | — | %1,7 | 7 Şub 2024 |
24İzleyin | CVE-2020-9440İstismar yok | A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web scrckeditor · ckeditor · CWE-79 | Orta6,1 | — | %1,3 | 10 Mar 2020 |
24İzleyin | CVE-2018-11093İstismar yok | Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web scckeditor · ckeditor 5-link · CWE-79 | Orta6,1 | — | %1,0 | 22 May 2018 |
24İzleyin | CVE-2023-28439İstismar yok | ckeditor4 plugins vulnerable to cross-site scripting caused by the editor instance destroying processckeditor · ckeditor · CWE-79 | Orta6,1 | — | %0,7 | 22 Mar 2023 |
24İzleyin | CVE-2024-24815İstismar yok | CKEditor4 Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detectionckeditor · ckeditor · CWE-79 | Orta6,1 | — | %0,7 | 7 Şub 2024 |
24İzleyin | CVE-2024-43407İstismar yok | Code Snippet GeSHi plugin has reflected cross-site scripting (XSS) vulnerabilityckeditor · ckeditor · CWE-79 | Orta6,1 | — | %0,5 | 21 Ağu 2024 |
24İzleyin | CVE-2026-28343İstismar yok | CKEditor: Cross-site scripting (XSS) in the HTML Support packageckeditor · ckeditor5 · CWE-79 | Orta6,1 | — | %0,3 | 5 Mar 2026 |
21İzleyin | CVE-2021-41165İstismar yok | HTML comments vulnerability allowing to execute JavaScript codeckeditor · ckeditor · CWE-79 | Orta5,4 | — | %1,6 | 17 Kas 2021 |
21İzleyin | CVE-2021-41164İstismar yok | Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTMLckeditor · ckeditor · CWE-79 | Orta5,4 | — | %1,3 | 17 Kas 2021 |
21İzleyin | CVE-2021-37695İstismar yok | Execution of JavaScript code using malformed HTML in ckeditorckeditor · ckeditor · CWE-79 | Orta5,4 | — | %1,3 | 12 Ağu 2021 |
21İzleyin | CVE-2022-24728İstismar yok | Cross-site Scripting in CKEditor4ckeditor · ckeditor · CWE-79 | Orta5,4 | — | %1,2 | 16 Mar 2022 |
- CVE-2023-3154139İzleyin
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine,
KritikCVSS 9,8Kavram kanıtıEPSS %1ckeditor · ckeditor13 Haz 2023
- CVE-2022-2472931İzleyin
Regular expression Denial of Service in dialog plugin
YüksekCVSS 7,5İstismar yokEPSS %2ckeditor · ckeditor16 Mar 2022
- CVE-2011-497231İzleyin
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attacke
YüksekCVSS 7,5İstismar yokEPSS %2ckeditor · ckeditor13 Kas 2019
- CVE-2021-2627227İzleyin
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the
OrtaCVSS 6,5İstismar yokEPSS %2ckeditor · ckeditor26 Oca 2021
- CVE-2021-2627127İzleyin
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles in
OrtaCVSS 6,5İstismar yokEPSS %2ckeditor · ckeditor26 Oca 2021
- CVE-2021-2125427İzleyin
Regular expression Denial of Service in Markdown plugin
OrtaCVSS 6,5İstismar yokEPSS %2ckeditor · ckeditor529 Oca 2021
- CVE-2021-2139127İzleyin
Regular expression Denial of Service in multiple packages
OrtaCVSS 6,5İstismar yokEPSS %2ckeditor · ckeditor5-engine28 Nis 2021
- CVE-2012-206727İzleyin
Unspecified vulnerability in the CKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.
OrtaCVSS 6,8İstismar yokEPSS %2ckeditor · fckeditor4 Eyl 2012
- CVE-2020-928125İzleyin
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitra
OrtaCVSS 6,1İstismar yokEPSS %4ckeditor · ckeditor6 Mar 2020
- CVE-2021-3382925İzleyin
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attack
OrtaCVSS 6,1Kavram kanıtıEPSS %3ckeditor · ckeditor9 Haz 2021
- CVE-2022-4811025İzleyin
CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget.
OrtaCVSS 6,1Kavram kanıtıEPSS %2ckeditor · ckeditor13 Şub 2023
- CVE-2020-2719325İzleyin
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web scrip
OrtaCVSS 6,1İstismar yokEPSS %2ckeditor · ckeditor12 Kas 2020
- CVE-2018-1796025İzleyin
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
OrtaCVSS 6,1İstismar yokEPSS %2ckeditor · ckeditor14 Kas 2018
- CVE-2018-986125İzleyin
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in
OrtaCVSS 6,1İstismar yokEPSS %2ckeditor · enhanced image19 Nis 2018
- CVE-2024-2481624İzleyin
Cross-site scripting (XSS) vulnerability in samples with enabled the preview feature
OrtaCVSS 6,1Kavram kanıtıEPSS %2ckeditor · ckeditor7 Şub 2024
- CVE-2020-944024İzleyin
A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web scr
OrtaCVSS 6,1İstismar yokEPSS %1ckeditor · ckeditor10 Mar 2020
- CVE-2018-1109324İzleyin
Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web sc
OrtaCVSS 6,1İstismar yokEPSS %1ckeditor · ckeditor 5-link22 May 2018
- CVE-2023-2843924İzleyin
ckeditor4 plugins vulnerable to cross-site scripting caused by the editor instance destroying process
OrtaCVSS 6,1İstismar yokEPSS %1ckeditor · ckeditor22 Mar 2023
- CVE-2024-2481524İzleyin
CKEditor4 Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detection
OrtaCVSS 6,1İstismar yokEPSS %1ckeditor · ckeditor7 Şub 2024
- CVE-2024-4340724İzleyin
Code Snippet GeSHi plugin has reflected cross-site scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0ckeditor · ckeditor21 Ağu 2024
- CVE-2026-2834324İzleyin
CKEditor: Cross-site scripting (XSS) in the HTML Support package
OrtaCVSS 6,1İstismar yokEPSS %0ckeditor · ckeditor55 Mar 2026
- CVE-2021-4116521İzleyin
HTML comments vulnerability allowing to execute JavaScript code
OrtaCVSS 5,4İstismar yokEPSS %2ckeditor · ckeditor17 Kas 2021
- CVE-2021-4116421İzleyin
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
OrtaCVSS 5,4İstismar yokEPSS %1ckeditor · ckeditor17 Kas 2021
- CVE-2021-3769521İzleyin
Execution of JavaScript code using malformed HTML in ckeditor
OrtaCVSS 5,4İstismar yokEPSS %1ckeditor · ckeditor12 Ağu 2021
- CVE-2022-2472821İzleyin
Cross-site Scripting in CKEditor4
OrtaCVSS 5,4İstismar yokEPSS %1ckeditor · ckeditor16 Mar 2022