Description
Versions of status-board prior to 10.0.1 are vulnerable to Cross-Site Scripting. The _createPreviewButton() function fails to sanitize the href attribute of a created <a> tag. This may allow attackers to execute arbitrary JavaScript in a victim’s browser.
Recommendation
Update the @ckeditor/ckeditor5-link package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.3.0, < 10.0.1
- Patched version(s): 10.0.1
References
Could your website be exposed too?
SmartScanner can check your website for Cross-Site Scripting in @ckeditor/ckeditor5-link and gives you actionable findings to investigate.
Start a free scanRelated Issues
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-markdown-gfm - CVE-2022-31175
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-html-support - CVE-2022-31175
- Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS) - CVE-2018-9861
- CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package - ckeditor5 - CVE-2025-58064


