Show filters
93 Total Results
Displaying 41-50 of 93
Sort by:
Attacker Value
Unknown

CVE-2021-21391

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-gfm, ckeditor5-media-embed, ckeditor5-paste-from-office, and ckeditor5-widget. Following an internal audit, a regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which could cause a significant performance drop resulting in a browser tab freeze. It affects all users using the CKEditor 5 packages listed above at version <= 26.0.0. The problem has been recognized and patched. The fix will be available in version 27.0.0.
Attacker Value
Unknown

CVE-2021-24154

Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd
Attacker Value
Unknown

CVE-2021-21254

Disclosure Date: January 29, 2021 (last updated February 22, 2025)
CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ckeditor/ckeditor5-markdown-gfm) before version 25.0.0 has a regex denial of service (ReDoS) vulnerability. The vulnerability allowed to abuse link recognition regular expression, which could cause a significant performance drop resulting in browser tab freeze. It affects all users using CKEditor 5 Markdown plugin at version <= 24.0.0. The problem has been recognized and patched. The fix will be available in version 25.0.0.
Attacker Value
Unknown

CVE-2021-26271

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
Attacker Value
Unknown

CVE-2021-26272

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
Attacker Value
Unknown

CVE-2020-23849

Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.
Attacker Value
Unknown

CVE-2020-27193

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
Attacker Value
Unknown

CVE-2020-9440

Disclosure Date: March 10, 2020 (last updated February 21, 2025)
A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.
Attacker Value
Unknown

CVE-2020-9281

Disclosure Date: March 07, 2020 (last updated February 21, 2025)
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Attacker Value
Unknown

CVE-2012-5867

Disclosure Date: January 23, 2020 (last updated February 21, 2025)
HT Editor 2.0.20 has a Remote Stack Buffer Overflow Vulnerability