Description
The vulnerability has been discovered in clipboard plugin. All plugins with clipboard plugin dependency are affected:
- clipboard
- pastetext
- pastetools
- widget
- uploadwidget
- autolink
- tableselection
Recommendation
Update the ckeditor4 package to the latest compatible version. Followings are version details:
- Affected version(s): >= 4.5.2, < 4.16.2
- Patched version(s): 4.16.2
References
Could your website be exposed too?
SmartScanner can check your website for Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Widget feature vulnerability allowing to execute JavaScript code using undo functionality - CVE-2021-32808
- Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML. - CVE-2021-37695
- Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML - CVE-2021-41164
- HTML comments vulnerability allowing to execute JavaScript code - CVE-2021-41165
You might also like:
See something that needs correcting? Let us knowUpdated February 01, 2023


