📦

ckeditor

Vendor: ckeditor

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 1 Remote Access
Total CVEs 41 Total Indexed
Avg. EPSS 1.64% Exploit Prob.
Latest CVE CVE-2024-43407 Aug 21

Security Vulnerability Index

Page 3 / 5
7.5 CVSS

hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.

EPSS: 1.74%
6.1 CVSS

The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.

EPSS: 0.91%
6.1 CVSS

CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.

EPSS: 1.95%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: 1.83%
6.8 CVSS

Unspecified vulnerability in the CKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.7 for Drupal, when the core PHP module is enabled, allows remote authenticated users or remote attackers to execute arbitrary PHP code via the text parameter to a text filter. NOTE: some of these details are obtained from third party information.

EPSS: 1.53%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in the FCKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.7 for Drupal allows remote authenticated users or remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: 1.36%