CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Ckeditor DrupalFedoraproject+1 more9Application Express CkeditorCommerce Merchandising+6 moreJun 17, 2026 Mar 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular...Show more |
4Ckeditor DrupalFedoraproject+1 more9Application Express CkeditorCommerce Merchandising+6 moreJun 17, 2026 Mar 16, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vuln...Show more |
4Ckeditor DebianFedoraproject+1 more12Application Express Banking Party ManagementCkeditor+9 moreJun 17, 2026 Aug 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability...Show more |
3Ckeditor FedoraprojectOracle10Application Express Banking Party ManagementCkeditor+7 moreJun 17, 2026 Aug 12, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allo...Show more |
3Ckeditor FedoraprojectOracle13Application Express Banking Party ManagementCkeditor+10 moreJun 17, 2026 Aug 12, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse un...Show more |
2Ckeditor Oracle10Agile Plm Application ExpressBanking Party Management+7 moreJun 17, 2026 Jan 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin). |
2Ckeditor Oracle9Agile Plm Application ExpressBanking Party Management+6 moreJun 17, 2026 Nov 12, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor...Show more |
1Oracle 1Commerce Merchandising Jun 17, 2026 Apr 23, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Vulnerability in the Oracle Commerce Merchandising component of Oracle Commerce (subcomponent: Asset Manager). The supported version that is affected is 11.2.0.3. Easily exploitable vulnerability allows unauthenticated a...Show more |