Description
The vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4.
Recommendation
Update the ckeditor4 package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.18.0
- Patched version(s): 4.18.0
References
Could your website be exposed too?
SmartScanner can check your website for Cross-site Scripting in CKEditor4 and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Toast UI Grid vulnerable to Cross-site Scripting - CVE-2022-23458
- materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input - CVE-2022-25349
- Cross-site Scripting in jquery.json-viewer - CVE-2022-30241
- CKEditor cross-site scripting vulnerability in AJAX sample - CVE-2023-4771
You might also like:
See something that needs correcting? Let us knowUpdated January 27, 2023


