CVE-2022-24728

MEDIUM

CKEditor4 <4.18.0 - XSS

Title source: llm
STIX 2.1

Description

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

Scores

CVSS v3 5.4
EPSS 0.0099
EPSS Percentile 77.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (18)
ckeditor/ckeditor 4.0 - 4.18.0
drupal/drupal 8.0.0 - 9.2.15
fedoraproject/fedora 36
fedoraproject/fedora 37
npm/ckeditor4 0 - 4.18.0npm
oracle/application_express < 22.1.1
oracle/commerce_merchandising 11.3.2
oracle/financial_services_analytical_applications_infrastructure 8.1.1.0
oracle/financial_services_analytical_applications_infrastructure 8.1.2.0
oracle/financial_services_analytical_applications_infrastructure 8.1.2.1
... and 8 more
Published Mar 16, 2022
Tracked Since Feb 18, 2026