ckeditor4
13 known vulnerabilities · 0 critical · 4 high
Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4
Improper Neutralization of Input During Web Page Generation in CKEditor4
Widget feature vulnerability allowing to execute JavaScript code using undo functionality
Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality
Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability
HTML comments vulnerability allowing to execute JavaScript code
CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML.