CVE-2020-9281Medium· 6.1▾ SunlitA cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.9 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.3%
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
ckeditor >= 4.0, < 4.14fedora = 30fedora = 31fedora = 32drupal >= 8.7.0, < 8.7.12drupal >= 8.8.0, < 8.8.4agile_product_lifecycle_management = 9.3.5agile_product_lifecycle_management = 9.3.6application_express < 20.2jd_edwards_enterpriseone_tools < 9.2.5.2peoplesoft_enterprise_peopletoolspeoplesoft_enterprise_peopletools = 8.56peoplesoft_enterprise_peopletools = 8.57peoplesoft_enterprise_peopletools = 8.58siebel_apps_-_customer_order_management < 21.0webcenter_portal = 11.1.1.9.0webcenter_portal = 12.2.1.3.0webcenter_portal = 12.2.1.4.0banking_enterprise_default_management = 2.6.2banking_enterprise_default_management = 2.7.0banking_enterprise_default_management = 2.7.1banking_enterprise_default_management = 2.10.0banking_enterprise_default_management = 2.12.0banking_enterprise_default_managment >= 2.3.0, <= 2.4.0Upgrade past the affected range:
ckeditor 4.14drupal 8.8.4application_express 20.2jd_edwards_enterpriseone_tools 9.2.5.2siebel_apps_-_customer_order_management 21.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor
CVE-2020-27193Medium· 6.1A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
CVE-2021-26272Medium· 6.5It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
CVE-2021-26271Medium· 6.5It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
CVE-2019-10219Medium· 6.1A vulnerability was found in Hibernate-Validator
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library