296,136
Total vulnerabilities in the database
A Cross-Site Scripting (XSS) vulnerability has been discovered in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration.
This vulnerability affects only installations where the editor configuration meets one of the following criteria:
RawElement
is enabledThe problem has been recognized and patched. The fix will be available in version 46.0.3 (and above), and explicitly in version 45.2.2.
Email us at security@cksource.com if you have any questions or comments about this advisory.
Software | From | Fixed in |
---|---|---|
![]() |
46.0.0 | 46.0.3 |
![]() |
44.2.0 | 45.2.2 |
![]() |
44.2.0 | 45.2.2 |
![]() |
46.0.0 | 46.0.3 |