Vulnerability library
Security checkMarch 19, 2026

CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package - @ckeditor/ckeditor5-html-support

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A Cross-Site Scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration.

Recommendation

Update the @ckeditor/ckeditor5-html-support package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 29.0.0, < 47.6.0
  • Patched version(s): 47.6.0

References

Could your website be exposed too?

SmartScanner can check your website for CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package - @ckeditor/ckeditor5-html-support and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated March 19, 2026