Ckeditor / Ckeditor5
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-28343 | CKEditor: Cross-site scripting (XSS) in the HTML Support package | MEDIUM | 6.4 | Mar 5, 2026 |
| CVE-2025-61261 | A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute arbitrary code in the context of a user'… | MEDIUM | 5.4 | Nov 7, 2025 |
| CVE-2025-58064 | CKEditor is susceptible to Cross-Site Scripting (XSS) through its clipboard package | LOW | 2.3 | Sep 3, 2025 |
| CVE-2025-25299 | Cross-site scripting (XSS) in the real-time collaboration package | MEDIUM | 6.9 | Feb 20, 2025 |
| CVE-2024-45613 | CKEditor 5 has Cross-site Scripting vulnerability in the clipboard package | MEDIUM | 5.1 | Sep 25, 2024 |
| CVE-2022-31175 | Cross-site scripting caused by the editor instance destroying process in ckeditor5 | MEDIUM | 5.8 | Aug 3, 2022 |
| CVE-2021-21391 | Regular expression Denial of Service in multiple packages | MEDIUM | 6.5 | Apr 29, 2021 |
| CVE-2021-21254 | Regular expression Denial of Service in Markdown plugin | MEDIUM | 6.5 | Jan 29, 2021 |
Showing 1 to 8 of 8 CVEs