Show filters
93 Total Results
Displaying 31-40 of 93
Sort by:
Attacker Value
Unknown

CVE-2021-39318

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found in the ~/h5p-css-editor.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.
0
Attacker Value
Unknown

CVE-2021-41165

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.
Attacker Value
Unknown

CVE-2021-41164

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.
Attacker Value
Unknown

CVE-2021-3822

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
jsoneditor is vulnerable to Inefficient Regular Expression Complexity
Attacker Value
Unknown

CVE-2020-23478

Disclosure Date: September 22, 2021 (last updated February 23, 2025)
Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py.
Attacker Value
Unknown

CVE-2021-37695

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.
Attacker Value
Unknown

CVE-2021-32809

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.
Attacker Value
Unknown

CVE-2021-32808

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2.
Attacker Value
Unknown

CVE-2021-24367

Disclosure Date: June 21, 2021 (last updated February 22, 2025)
The WP Config File Editor WordPress plugin through 1.7.1 was affected by an Authenticated Stored Cross-Site Scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2021-33829

Disclosure Date: June 09, 2021 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.