CVE-2021-26271Medium· 6.5▾ SunlitIt was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.0%
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
ckeditor >= 4.0, < 4.16agile_product_lifecycle_management = 9.3.5agile_product_lifecycle_management = 9.3.6application_express < 21.1.0financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9financial_services_analytical_applications_infrastructure = 8.1.0financial_services_analytical_applications_infrastructure = 8.1.1jd_edwards_enterpriseone_tools < 9.2.6.0siebel_ui_framework < 21.9webcenter_sites = 12.2.1.3.0webcenter_sites = 12.2.1.4.0Upgrade past the affected range:
ckeditor 4.16application_express 21.1.0jd_edwards_enterpriseone_tools 9.2.6.0siebel_ui_framework 21.9Connected by shared product, vendor, weakness, or advisory.
CVE-2021-26272Medium· 6.5It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
CVE-2020-27193Medium· 6.1A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
CVE-2020-9281Medium· 6.1A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor
CVE-2025-70974Critical· 10.0Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class
CVE-2026-49449Low· 2.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks