Total vulnerabilities in the database
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
Software | From | Fixed in |
---|---|---|
ckeditor / ckeditor | 4.14.0 | 4.16.1 |
fedoraproject / fedora | 33 | 33.x |
fedoraproject / fedora | 34 | 34.x |
fedoraproject / fedora | 35 | 35.x |
drupal / drupal | 9.1.0 | 9.1.9 |
drupal / drupal | 9.0.0 | 9.0.14 |
drupal / drupal | 8.9.0 | 8.9.16 |
debian / debian_linux | 9.0 | 9.0.x |
![]() |
4.14.0 | 4.16.1 |