Vulnerabilities/

Cross-site scripting in CKEditor5

Severity:
Medium

Description

CKSource CKEditor5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget.

NOTE: the vendor’s position is that this is not a vulnerability.

Recommendation

Update the ckeditor5 package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ckeditor5
Anything's wrong? Let us know Last updated on February 23, 2023