CVE-2020-27193Medium· 6.1▾ SunlitA cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.0%
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
ckeditor = 4.15.0agile_product_lifecycle_management = 9.3.5agile_product_lifecycle_management = 9.3.6application_express < 21.1.0.00.01banking_party_management = 2.7.0banking_platform = 2.4.0banking_platform = 2.7.0banking_platform = 2.7.1banking_platform = 2.8.0banking_platform = 2.9.0commerce_merchandising = 11.0.0commerce_merchandising = 11.1.0commerce_merchandising = 11.2.0commerce_merchandising = 11.3.0commerce_merchandising = 11.3.1commerce_merchandising = 11.3.2financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9financial_services_analytical_applications_infrastructure = 8.1.0financial_services_analytical_applications_infrastructure = 8.1.1jd_edwards_enterpriseone_tools < 9.2.6.0peoplesoft_enterprise_peopletools = 8.56peoplesoft_enterprise_peopletools = 8.57peoplesoft_enterprise_peopletools = 8.58Upgrade past the affected range:
application_express 21.1.0.00.01jd_edwards_enterpriseone_tools 9.2.6.0Connected by shared product, vendor, weakness, or advisory.
CVE-2020-9281Medium· 6.1A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
CVE-2021-26272Medium· 6.5It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
CVE-2021-26271Medium· 6.5It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41183Medium· 6.5jQuery-UI is the official jQuery user interface library