CVE-2021-41164High· 8.2▾ TwilightCKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malf…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.3%
1.3% → 1.3%
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.
ckeditor >= 4.0, < 4.17.0drupal >= 8.9.0, < 8.9.20drupal >= 9.1.0, < 9.1.14drupal >= 9.2.0, < 9.2.9banking_apis >= 18.1, <= 18.3banking_apis = 19.1banking_apis = 19.2banking_apis = 20.1banking_apis = 21.1banking_digital_experience >= 18.1, <= 18.3banking_digital_experience = 19.1banking_digital_experience = 19.2banking_digital_experience = 20.1banking_digital_experience = 21.1agile_product_lifecycle_management = 9.3.6application_express < 22.1commerce_guided_search = 11.3.2peoplesoft_enterprise_peopletools = 8.58peoplesoft_enterprise_peopletools = 8.59webcenter_portal = 12.2.1.3.0webcenter_portal = 12.2.1.4.0fedora = 36fedora = 37Upgrade past the affected range:
ckeditor 4.17.0drupal 9.2.9application_express 22.1Connected by shared product, vendor, weakness, or advisory.
CVE-2020-9281Medium· 6.1A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41183Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41182Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-26272Medium· 6.5It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
CVE-2019-10219Medium· 6.1A vulnerability was found in Hibernate-Validator