Vulnerabilities/

ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor

Severity:
Medium

Description

It has been discovered that the ckeditor-wordcount-plugin plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode.

Recommendation

Update the ckeditor-wordcount-plugin package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ckeditor-wordcount-plugin
Anything's wrong? Let us know Last updated on November 09, 2023