CVE-2021-32809 PUBLISHED

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.

EPSS 0.32% · 55.0th percentile

Risk Scores

EPSS Score
0.32%
55.0th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSckeditor0, 4.12.1+dfsg-1, 4.11.1+dfsg-1
Ubuntu:18.04:LTSckeditor0, 4.5.7+dfsg-2
Ubuntu:Pro:16.04:LTSckeditor0, 4.4.4+dfsg1-3, 4.5.7+dfsg-1

Timeline

References

Open in Interactive Console →