Show filters
49 Total Results
Displaying 31-40 of 49
Sort by:
Attacker Value
Unknown

CVE-2011-4972

Disclosure Date: November 13, 2019 (last updated November 27, 2024)
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.
Attacker Value
Unknown

CVE-2015-9349

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.
0
Attacker Value
Unknown

CVE-2018-17960

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
0
Attacker Value
Unknown

CVE-2018-11093

Disclosure Date: May 22, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.
Attacker Value
Unknown

CVE-2014-5191

Disclosure Date: August 07, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-4037

Disclosure Date: June 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor before 2.6.11 and earlier allows remote attackers to inject arbitrary web script or HTML via an array key in the textinputs[] parameter, a different issue than CVE-2012-4000.
0
Attacker Value
Unknown

CVE-2012-2066

Disclosure Date: September 05, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the FCKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.7 for Drupal allows remote authenticated users or remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-2067

Disclosure Date: September 05, 2012 (last updated October 05, 2023)
Unspecified vulnerability in the CKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.7 for Drupal, when the core PHP module is enabled, allows remote authenticated users or remote attackers to execute arbitrary PHP code via the text parameter to a text filter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2012-4000

Disclosure Date: July 12, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor 2.6.7 and earlier allows remote attackers to inject arbitrary web script or HTML via textinputs array parameters.
0
Attacker Value
Unknown

CVE-2009-4875

Disclosure Date: May 26, 2010 (last updated October 04, 2023)
FCKeditor.Java 2.4 allows remote attackers to cause a denial of service (infinite loop) via a malformed request parameter that contains "ctrl" characters.
0