Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability
- Severity:
- Medium
Description
The vulnerability has been discovered in Code Snippet GeSHi plugin. All integrators that use GeSHi syntax highlighter on the backend side can be affected.
Recommendation
Update the ckeditor4 package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.25.0
- Patched version(s): 4.25.0
References
Related Issues
- VvvebJs Reflected Cross-Site Scripting (XSS) vulnerability - CVE-2024-29271
- CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover - CVE-2024-43411
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
- vue-i18n has cross-site scripting vulnerability with prototype pollution - @intlify/vue-i18n-core - CVE-2024-52809
You might also like:
- Tags:
- npm
- ckeditor4
Anything's wrong? Let us know Last updated on February 18, 2025


