Vulnerabilities (CVE)

Filtered by vendor Ckeditor
Filtered by product Ckeditor5-html-support
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-31175 1 Ckeditor 3 Ckeditor5-html-embed, Ckeditor5-html-support, Ckeditor5-markdown-gfm 2024-11-21 N/A 5.8 MEDIUM
CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript code after fulfilling special conditions. The affected packages are `@ckeditor/ckeditor5-markdown-gfm`, `@ckeditor/ckeditor5-html-support`, and `@ckeditor/ckeditor5-html-embed`. The specific conditions are 1) Using one of the affected packages. In case of `ckeditor5-html- ...

Show More