CVE-2019-9870
CRITICALoembed < 2019-03-14 - Cross-Site Scripting via SCRIPT Element Mishandling
Title source: llmDescription
plugin.js in the w8tcha oEmbed plugin before 2019-03-14 for CKEditor mishandles SCRIPT elements.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://github.com/w8tcha/CKEditor-oEmbed-Plugin/issues/94
Patch, Third Party Advisory x_refsource_misc
https://github.com/w8tcha/CKEditor-oEmbed-Plugin/commit/10f6169e39510bbf5af913886037044458b9dc9b
Scores
CVSS v3
9.8
EPSS
0.0185
EPSS Percentile
76.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-19
Status
published
Products (1)
oembed_project/oembed
< 2019-03-14
Published
Mar 21, 2019
Tracked Since
Feb 18, 2026