CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-03-16T00:00:00.000Z
Updated: 2025-04-23T18:53:42.950Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24728

Updated: 2024-08-03T04:20:49.856Z

Status : Modified
Published: 2022-03-16T16:15:10.907
Modified: 2024-11-21T06:50:57.820
Link: CVE-2022-24728

No data.