4.25.0
5 years ago
3 months ago
Known vulnerabilities in the ckeditor4 package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
ckeditor4 is a JavaScript WYSIWYG web text editor. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization via the How to fix Cross-site Scripting (XSS)? Upgrade | <4.25.0 |
ckeditor4 is a JavaScript WYSIWYG web text editor. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to incorrect CDATA detection in the HTML parsing module. This flaw allows for the injection of malformed HTML content that bypasses the Advanced Content Filtering mechanism, potentially leading to the execution of JavaScript code. An attacker could exploit this vulnerability by manipulating CDATA content detection to launch an attack on the editor. Note: This issue is particularly relevant for instances that have enabled full-page editing mode or have allowed CDATA elements in the Advanced Content Filtering configuration, which by default includes How to fix Cross-site Scripting (XSS)? Upgrade | <4.24.0 |
ckeditor4 is a JavaScript WYSIWYG web text editor. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to the misconfiguration of the Note: This issue affects samples that enable the preview feature, specifically within How to fix Cross-site Scripting (XSS)? Upgrade | <4.24.0 |
ckeditor4 is a JavaScript WYSIWYG web text editor. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | <4.24.0 |
ckeditor4 is a JavaScript WYSIWYG web text editor. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via malformed HTML injection to the core HTML processing module, which may allow execution of JavaScript code. How to fix Cross-site Scripting (XSS)? Upgrade | <4.18.0 |
ckeditor4 is a JavaScript WYSIWYG web text editor. Affected versions of this package are vulnerable to Remote Code Execution (RCE) via How to fix Remote Code Execution (RCE)? Upgrade | <4.15.1 |
ckeditor4 is a JavaScript WYSIWYG web text editor. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the Advanced Content Filter (ACF) module and may affect all plugins used by the package. How to fix Cross-site Scripting (XSS)? Upgrade | <4.17.0 |
ckeditor4 is a JavaScript WYSIWYG web text editor. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the core HTML processing module and may affect all plugins used by the package. How to fix Cross-site Scripting (XSS)? Upgrade | <4.17.0 |
ckeditor4 is a JavaScript WYSIWYG web text editor. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). A vulnerability has been discovered in CKEditor 4 Clipboard package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. How to fix Cross-site Scripting (XSS)? Upgrade | <4.16.2 |
ckeditor4 is a JavaScript WYSIWYG web text editor. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). A vulnerability has been discovered in CKEditor 4 Fake Objects package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. How to fix Cross-site Scripting (XSS)? Upgrade | <4.16.2 |
ckeditor4 is a JavaScript WYSIWYG web text editor. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2. How to fix Cross-site Scripting (XSS)? Upgrade | <4.16.2 |