MEDIUM
CKEditor: Cross-site scripting (XSS) in the HTML Support package
Published Mar 5, 2026
6.4
MEDIUMCVSS 3.1
EPSS 0.36%
Description
CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.
Affected products
-
- Version >= 29.0.0, < 47.6.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
@ckeditor/ckeditor5-html-support
npm
Introduced 29.0.0 Fixed 47.6.0ckeditor5
npm
Introduced 29.0.0 Fixed 47.6.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @ckeditor/ckeditor5-html-support | 29.0.0 | 47.6.0 |
| npm | ckeditor5 | 29.0.0 | 47.6.0 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-jrqm-vmqc-gm93 Advisory
- https://github.com/ckeditor/ckeditor5/releases/tag/v29.0.0 x_refsource_MISC
- https://github.com/ckeditor/ckeditor5/releases/tag/v47.6.0 x_refsource_MISCRelease Notes
- https://github.com/ckeditor/ckeditor5/security/advisories/GHSA-jrqm-vmqc-gm93 x_refsource_CONFIRMMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-28343
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-jrqm-vmqc-gm93 | Advisory | |
| https://github.com/ckeditor/ckeditor5/releases/tag/v29.0.0 | x_refsource_MISC | |
| https://github.com/ckeditor/ckeditor5/releases/tag/v47.6.0 | x_refsource_MISCRelease Notes | |
| https://github.com/ckeditor/ckeditor5/security/advisories/GHSA-jrqm-vmqc-gm93 | x_refsource_CONFIRMMitigationVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-28343 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 5, 2026
Updated Mar 19, 2026
Reserved Feb 26, 2026
Link CVE-2026-28343
CISA Vulnrichment
GHSA-JRQM-VMQC-GM93 Updated Mar 6, 2026