OsVault/npm/ckeditor
npm

ckeditor

19 known vulnerabilities · 0 critical · 0 high

CVE-2018-17960MEDIUM

Ckeditor XSS Vulnerability

Published Nov 21, 2018
CVE-2022-24728MEDIUM

Cross-site Scripting in CKEditor4

Published Mar 16, 2022
CVE-2021-26272MEDIUM

Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4

Published Oct 13, 2021
CVE-2020-27193MEDIUM

Improper Neutralization of Input During Web Page Generation in CKEditor4

Published May 24, 2022
MAL-2026-2667

Malicious code in ckeditor5-minimap (npm)

Published Apr 14, 2026
CVE-2022-31175MEDIUM

CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process

Published Aug 6, 2022
CVE-2024-43407MEDIUM

Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability

Published Aug 21, 2024
CVE-2018-9861MEDIUM

Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS)

Published May 14, 2022
MAL-2024-9201

Malicious code in uploadcare-ckeditor (npm)

Published Oct 9, 2024
CVE-2024-24815MEDIUM

CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection

Published Feb 7, 2024
CVE-2020-9281MEDIUM

CKEditor 4.0 vulnerability in the HTML Data Processor

Published May 7, 2021
CVE-2021-21254MEDIUM

CKEditor 5 Markdown plugin Regular expression Denial of Service

Published Jan 29, 2021
CVE-2026-28343

CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package

Published Mar 4, 2026
CVE-2023-37905MEDIUM

ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor

Published Jul 10, 2023
CVE-2025-43761

Liferay Portal Reflected XSS in CKeditor 4.21.0 endpoint

Published Aug 22, 2025
CVE-2018-11093MEDIUM

Cross-Site Scripting in @ckeditor/ckeditor5-link

Published May 23, 2018
CVE-2021-26271MEDIUM

CKEditor 4 ReDoS Vulnerability

Published May 24, 2022
CVE-2021-33829MEDIUM

ckeditor4 vulnerable to cross-site scripting

Published Jun 21, 2021
CVE-2023-4771MEDIUM

CKEditor cross-site scripting vulnerability in AJAX sample

Published Feb 7, 2024
Check your entire dependency tree at onceRun dependency scan →