pkg:npm/ckeditor4
15 total CVEsHIGH4MEDIUM10LOW1
✅ Check your installed version
All known vulnerabilities
- from 0, < 4.17.0
- HIGH8.2CVE-2021-41164Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTMLfrom 0, < 4.17.0
- HIGH7.6CVE-2021-32808Widget feature vulnerability allowing to execute JavaScript code using undo functionality>= 4.13.0, < 4.16.2
- HIGH7.3CVE-2021-37695Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML.from 0, < 4.16.2
- from 0, < 4.16.0
- MEDIUM6.1CVE-2024-43407Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerabilityfrom 0, < 4.25.0
- from 0, < 4.24.0-lts
- MEDIUM6.1CVE-2024-24816CKEditor4 Cross-site Scripting vulnerability in samples with enabled the preview featurefrom 0, < 4.24.0-lts
- MEDIUM6.1CVE-2024-24815CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detectionfrom 0, < 4.24.0-lts
- from 0, < 4.15.1
- >= 4.14.0, < 4.16.1
- from 0, < 4.14.0
- from 0, < 4.18.0
- MEDIUM4.6CVE-2021-32809Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality>= 4.5.2, < 4.16.2
- LOW3.1CVE-2024-43411CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover>= 4.22.0, < 4.25.0