Total vulnerabilities in the database
A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.
Software | From | Fixed in |
---|---|---|
ckeditor / ckeditor | 4.0 | 4.0.x |
webspellchecker / webspellchecker | - | 5.5.7.5.x |
fedoraproject / fedora | 30 | 30.x |
fedoraproject / fedora | 31 | 31.x |
fedoraproject / fedora | 32 | 32.x |