ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor
- Severity:
- Medium
Description
It has been discovered that the ckeditor-wordcount-plugin plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode.
Recommendation
Update the ckeditor-wordcount-plugin package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.17.11
- Patched version(s): 1.17.12
References
Related Issues
- Jodit Editor vulnerable to cross-site scripting - CVE-2023-42399
- editor.md vulnerable to Cross-site Scripting - CVE-2023-29641
- Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS) - CVE-2018-9861
- Froala Editor Cross-site Scripting vulnerability - CVE-2023-41592
You might also like:
- Tags:
- npm
- ckeditor-wordcount-plugin
Anything's wrong? Let us know Last updated on November 09, 2023


