---
id: CVE-2020-9281
title: >-
  A cross-site scripting (XSS) vulnerability in the HTML Data Processor for
  CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web
  script through a crafted "protected" comment (with the cke_protected syntax).
summary: >-
  A cross-site scripting (XSS) vulnerability in the HTML Data Processor for
  CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web
  script through a crafted "protected" comment (with the cke_protected syntax).
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: ckeditor
product: ckeditor
affected:
  - 'ckeditor >= 4.0, < 4.14'
  - fedora = 30
  - fedora = 31
  - fedora = 32
  - 'drupal >= 8.7.0, < 8.7.12'
  - 'drupal >= 8.8.0, < 8.8.4'
  - agile_product_lifecycle_management = 9.3.5
  - agile_product_lifecycle_management = 9.3.6
  - application_express < 20.2
  - jd_edwards_enterpriseone_tools < 9.2.5.2
  - peoplesoft_enterprise_peopletools
  - peoplesoft_enterprise_peopletools = 8.56
  - peoplesoft_enterprise_peopletools = 8.57
  - peoplesoft_enterprise_peopletools = 8.58
  - siebel_apps_-_customer_order_management < 21.0
  - webcenter_portal = 11.1.1.9.0
  - webcenter_portal = 12.2.1.3.0
  - webcenter_portal = 12.2.1.4.0
  - banking_enterprise_default_management = 2.6.2
  - banking_enterprise_default_management = 2.7.0
  - banking_enterprise_default_management = 2.7.1
  - banking_enterprise_default_management = 2.10.0
  - banking_enterprise_default_management = 2.12.0
  - 'banking_enterprise_default_managment >= 2.3.0, <= 2.4.0'
patched:
  - ckeditor 4.14
  - drupal 8.8.4
  - application_express 20.2
  - jd_edwards_enterpriseone_tools 9.2.5.2
  - siebel_apps_-_customer_order_management 21.0
published: '2020-03-07'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-9281'
references:
  - url: 'https://github.com/ckeditor/ckeditor4'
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7OJ4BSS3VEAEXPNSOOUAXX6RDNECGZNO/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L322YA73LCV3TO7ORY45WQDAFJVNKXBE/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M4HHYQ6N452XTCIROFMJOTYEUWSB6FR4/
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: cve@mitre.org
  - url: 'https://github.com/ckeditor/ckeditor4'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7OJ4BSS3VEAEXPNSOOUAXX6RDNECGZNO/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L322YA73LCV3TO7ORY45WQDAFJVNKXBE/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M4HHYQ6N452XTCIROFMJOTYEUWSB6FR4/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.04308
epssPercentile: 0.90738
ingestedAt: '2026-08-25T17:29:29.444Z'
---

## Overview

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

## Affected

- `ckeditor >= 4.0, < 4.14`
- `fedora = 30`
- `fedora = 31`
- `fedora = 32`
- `drupal >= 8.7.0, < 8.7.12`
- `drupal >= 8.8.0, < 8.8.4`
- `agile_product_lifecycle_management = 9.3.5`
- `agile_product_lifecycle_management = 9.3.6`
- `application_express < 20.2`
- `jd_edwards_enterpriseone_tools < 9.2.5.2`
- `peoplesoft_enterprise_peopletools`
- `peoplesoft_enterprise_peopletools = 8.56`
- `peoplesoft_enterprise_peopletools = 8.57`
- `peoplesoft_enterprise_peopletools = 8.58`
- `siebel_apps_-_customer_order_management < 21.0`
- `webcenter_portal = 11.1.1.9.0`
- `webcenter_portal = 12.2.1.3.0`
- `webcenter_portal = 12.2.1.4.0`
- `banking_enterprise_default_management = 2.6.2`
- `banking_enterprise_default_management = 2.7.0`
- `banking_enterprise_default_management = 2.7.1`
- `banking_enterprise_default_management = 2.10.0`
- `banking_enterprise_default_management = 2.12.0`
- `banking_enterprise_default_managment >= 2.3.0, <= 2.4.0`

## Remediation

Upgrade past the affected range:

- `ckeditor 4.14`
- `drupal 8.8.4`
- `application_express 20.2`
- `jd_edwards_enterpriseone_tools 9.2.5.2`
- `siebel_apps_-_customer_order_management 21.0`
