{"id":"CVE-2020-27193","title":"A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.","summary":"A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"ckeditor","product":"ckeditor","affected":["ckeditor = 4.15.0","agile_product_lifecycle_management = 9.3.5","agile_product_lifecycle_management = 9.3.6","application_express < 21.1.0.00.01","banking_party_management = 2.7.0","banking_platform = 2.4.0","banking_platform = 2.7.0","banking_platform = 2.7.1","banking_platform = 2.8.0","banking_platform = 2.9.0","commerce_merchandising = 11.0.0","commerce_merchandising = 11.1.0","commerce_merchandising = 11.2.0","commerce_merchandising = 11.3.0","commerce_merchandising = 11.3.1","commerce_merchandising = 11.3.2","financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9","financial_services_analytical_applications_infrastructure = 8.1.0","financial_services_analytical_applications_infrastructure = 8.1.1","jd_edwards_enterpriseone_tools < 9.2.6.0","peoplesoft_enterprise_peopletools = 8.56","peoplesoft_enterprise_peopletools = 8.57","peoplesoft_enterprise_peopletools = 8.58"],"patched":["application_express 21.1.0.00.01","jd_edwards_enterpriseone_tools 9.2.6.0"],"published":"2020-11-12","updated":"2026-08-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-27193","references":[{"url":"https://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released/","label":"cve@mitre.org"},{"url":"https://ckeditor.com/cke4/release/CKEditor-4.15.1","label":"cve@mitre.org"},{"url":"https://ckeditor.com/ckeditor-4/download/","label":"cve@mitre.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"cve@mitre.org"},{"url":"https://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ckeditor.com/cke4/release/CKEditor-4.15.1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ckeditor.com/ckeditor-4/download/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.02033,"epssPercentile":0.79944,"ingestedAt":"2026-08-25T17:29:30.348Z","slug":"CVE-2020-27193","body":"## Overview\n\nA cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.\n\n## Affected\n\n- `ckeditor = 4.15.0`\n- `agile_product_lifecycle_management = 9.3.5`\n- `agile_product_lifecycle_management = 9.3.6`\n- `application_express < 21.1.0.00.01`\n- `banking_party_management = 2.7.0`\n- `banking_platform = 2.4.0`\n- `banking_platform = 2.7.0`\n- `banking_platform = 2.7.1`\n- `banking_platform = 2.8.0`\n- `banking_platform = 2.9.0`\n- `commerce_merchandising = 11.0.0`\n- `commerce_merchandising = 11.1.0`\n- `commerce_merchandising = 11.2.0`\n- `commerce_merchandising = 11.3.0`\n- `commerce_merchandising = 11.3.1`\n- `commerce_merchandising = 11.3.2`\n- `financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9`\n- `financial_services_analytical_applications_infrastructure = 8.1.0`\n- `financial_services_analytical_applications_infrastructure = 8.1.1`\n- `jd_edwards_enterpriseone_tools < 9.2.6.0`\n- `peoplesoft_enterprise_peopletools = 8.56`\n- `peoplesoft_enterprise_peopletools = 8.57`\n- `peoplesoft_enterprise_peopletools = 8.58`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `application_express 21.1.0.00.01`\n- `jd_edwards_enterpriseone_tools 9.2.6.0`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}