Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ckeditor5 MEDIUM 6.1
CVE-2026-28343

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scr…

Fix: 47.6.0+
Fix from $1,600 2026-03-05
Ckeditor5 MEDIUM 6.1
CVE-2024-45613

CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is pr…

Fix: 43.1.1+
Fix from $1,600 2024-09-25
Ckeditor MEDIUM 6.1
CVE-2024-43407

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in CKEditor 4 Code Snippet GeSHi …

Fix: 4.25.0+
Fix from $1,600 2024-08-21
Ckeditor MEDIUM 6.1
CVE-2024-24816

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versi…

Fix: 4.24.0+
Fix from $1,600 2024-02-07
Ckeditor MEDIUM 6.1
CVE-2024-24815

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsi…

Fix: 4.24.0+
Fix from $1,600 2024-02-07
Ckeditor CRITICAL 9.8
CVE-2023-31541

A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which al…

Mitigation only
Fix from $2,300 2023-06-13
Ckeditor MEDIUM 6.1
CVE-2022-48110

CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the ven…

No fix yet
Fix from $1,600 2023-02-13
Ckeditor5 Engine MEDIUM 6.5
CVE-2021-21391

CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckedi…

Fix: 27.0.0+
Fix from $1,600 2021-04-29
Ckeditor5 MEDIUM 6.5
CVE-2021-21254

CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ckeditor/ckeditor5-markdown-gfm…

Fix: 25.0.0+
Fix from $1,600 2021-01-29
Ckeditor MEDIUM 6.5
CVE-2021-26271

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of sp…

Fix: 4.16 / 9.2.6.0+
Fix from $1,600 2021-01-26
Ckeditor MEDIUM 6.5
CVE-2021-26272

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, a…

Fix: 4.16 / 9.2.6.0+
Fix from $1,600 2021-01-26
Ckeditor MEDIUM 6.1
CVE-2020-27193

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after p…

Fix: 9.2.6.0 / 21.1.0.00.01+
Fix from $1,600 2020-11-12
Ckeditor HIGH 7.5
CVE-2011-4972

hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to rea…

Patch available
Fix from $1,950 2019-11-13
Ckeditor MEDIUM 6.1
CVE-2018-17960

CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.

Fix: 4.11.0+
Fix from $1,600 2018-11-14
Ckeditor 5 Link MEDIUM 6.1
CVE-2018-11093

Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script thro…

Fix: 10.0.1+
Fix from $1,600 2018-05-22
Fckeditor MEDIUM 6.8
CVE-2012-2067

Unspecified vulnerability in the CKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.7 for…

Patch available
Fix from $1,600 2012-09-05