CVE-2024-43407
- EPSS 0.89%
- Published 21.08.2024 15:15:09
- Last modified 23.08.2024 16:20:42
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in CKEditor 4 Code Snippet GeSHi plugin. The vulnerability allowed a reflected XSS attack by exploiting a flaw in the GeSHi syntax hig...
CVE-2024-24816
- EPSS 21.58%
- Published 07.02.2024 17:15:11
- Last modified 21.11.2024 08:59:46
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior to 4.24.0-lts in samples that use the `preview` feature. All integrators that use these sam...
CVE-2024-24815
- EPSS 0.12%
- Published 07.02.2024 16:15:47
- Last modified 21.11.2024 08:59:46
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0-lts. It may affect all editor instances that enabl...
CVE-2023-31541
- EPSS 4.21%
- Published 13.06.2023 17:15:14
- Last modified 03.01.2025 20:15:26
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
CVE-2023-28439
- EPSS 0.24%
- Published 22.03.2023 21:15:18
- Last modified 21.11.2024 07:55:04
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed packages. The vulnerability may trigger a JavaScript code after fulfilling special ...
CVE-2022-48110
- EPSS 0.88%
- Published 13.02.2023 20:15:10
- Last modified 24.03.2025 13:15:24
CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation discusses that it is...
CVE-2022-24729
- EPSS 0.51%
- Published 16.03.2022 17:15:07
- Last modified 21.11.2024 06:50:57
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a ...
CVE-2022-24728
- EPSS 0.72%
- Published 16.03.2022 16:15:10
- Last modified 21.11.2024 06:50:57
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to in...
CVE-2021-41165
- EPSS 0.11%
- Published 17.11.2021 20:15:10
- Last modified 21.11.2024 06:25:38
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML byp...
CVE-2021-41164
- EPSS 0.06%
- Published 17.11.2021 19:15:08
- Last modified 21.11.2024 06:25:38
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML by...