---
id: CVE-2020-27193
title: >-
  A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for
  CKEditor 4.15.0 allows remote attackers to run arbitrary web script after
  persuading a user to copy and paste crafted HTML code into one of editor
  inputs.
summary: >-
  A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for
  CKEditor 4.15.0 allows remote attackers to run arbitrary web script after
  persuading a user to copy and paste crafted HTML code into one of editor
  inputs.
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: ckeditor
product: ckeditor
affected:
  - ckeditor = 4.15.0
  - agile_product_lifecycle_management = 9.3.5
  - agile_product_lifecycle_management = 9.3.6
  - application_express < 21.1.0.00.01
  - banking_party_management = 2.7.0
  - banking_platform = 2.4.0
  - banking_platform = 2.7.0
  - banking_platform = 2.7.1
  - banking_platform = 2.8.0
  - banking_platform = 2.9.0
  - commerce_merchandising = 11.0.0
  - commerce_merchandising = 11.1.0
  - commerce_merchandising = 11.2.0
  - commerce_merchandising = 11.3.0
  - commerce_merchandising = 11.3.1
  - commerce_merchandising = 11.3.2
  - 'financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9'
  - financial_services_analytical_applications_infrastructure = 8.1.0
  - financial_services_analytical_applications_infrastructure = 8.1.1
  - jd_edwards_enterpriseone_tools < 9.2.6.0
  - peoplesoft_enterprise_peopletools = 8.56
  - peoplesoft_enterprise_peopletools = 8.57
  - peoplesoft_enterprise_peopletools = 8.58
patched:
  - application_express 21.1.0.00.01
  - jd_edwards_enterpriseone_tools 9.2.6.0
published: '2020-11-12'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-27193'
references:
  - url: 'https://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released/'
    label: cve@mitre.org
  - url: 'https://ckeditor.com/cke4/release/CKEditor-4.15.1'
    label: cve@mitre.org
  - url: 'https://ckeditor.com/ckeditor-4/download/'
    label: cve@mitre.org
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: cve@mitre.org
  - url: 'https://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://ckeditor.com/cke4/release/CKEditor-4.15.1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://ckeditor.com/ckeditor-4/download/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02033
epssPercentile: 0.80244
ingestedAt: '2026-08-25T17:29:30.348Z'
---

## Overview

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

## Affected

- `ckeditor = 4.15.0`
- `agile_product_lifecycle_management = 9.3.5`
- `agile_product_lifecycle_management = 9.3.6`
- `application_express < 21.1.0.00.01`
- `banking_party_management = 2.7.0`
- `banking_platform = 2.4.0`
- `banking_platform = 2.7.0`
- `banking_platform = 2.7.1`
- `banking_platform = 2.8.0`
- `banking_platform = 2.9.0`
- `commerce_merchandising = 11.0.0`
- `commerce_merchandising = 11.1.0`
- `commerce_merchandising = 11.2.0`
- `commerce_merchandising = 11.3.0`
- `commerce_merchandising = 11.3.1`
- `commerce_merchandising = 11.3.2`
- `financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9`
- `financial_services_analytical_applications_infrastructure = 8.1.0`
- `financial_services_analytical_applications_infrastructure = 8.1.1`
- `jd_edwards_enterpriseone_tools < 9.2.6.0`
- `peoplesoft_enterprise_peopletools = 8.56`
- `peoplesoft_enterprise_peopletools = 8.57`
- `peoplesoft_enterprise_peopletools = 8.58`

## Remediation

Upgrade past the affected range:

- `application_express 21.1.0.00.01`
- `jd_edwards_enterpriseone_tools 9.2.6.0`
