CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover
- Severity:
- Medium
Description
The issue impacts only editor instances with enabled version notifications.
Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please contact us.
Recommendation
Update the ckeditor4 package to the latest compatible version. Followings are version details:
- Affected version(s): >= 4.22.0, < 4.25.0
- Patched version(s): 4.25.0
References
Related Issues
- Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability - CVE-2024-43407
- CKEditor4 Cross-site Scripting vulnerability in samples with enabled the preview feature - CVE-2024-24816
- CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection - CVE-2024-24815
- Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes - CVE-2024-6485
You might also like:
- Tags:
- npm
- ckeditor4
Anything's wrong? Let us know Last updated on November 18, 2024


