VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 17 hours ago
Reset
More filters (1)
Columns
Oracle product: Oracle PeopleSoft / Rich Text Editor (CKEditor)
Overview 5 matches · 2 in RASP scope · 0 protected · 0 KEV · 0 public PoC · 0 CISA SSVC · 0 EPSS ≥ 0.5 · 0 disputed
5matches 2in RASP scope40.0% 0protected0.0% 0KEV0.0% 0public PoC0.0% 0CISA SSVC0.0% 0EPSS ≥ 0.50.0% 0disputed0.0%
Critical 0 0.0% High 3 60.0% Medium 2 40.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 0 0.0% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 1 20.0% No fix identified 1 20.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 3 60.0% Rejected 0 0.0%
blocked by ARMR today 0 0.0% not blocked 5 100.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 0 0.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 5 100.0%
split by peak 1 / quarter
Unknown: 0None: 0Low: 0Medium: 2High: 3Critical: 0 Rejected: 0Out of RASP scope: 3Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 1No exploit published: 1Mitigation candidate: 0Rule in development: 0Protected by RASP: 0 unrecorded: 0not established: 0not blocked: 5blocked by ARMR today: 0 No public exploit: 5Forecast only: 0Proof of concept only: 0Working exploit published: 0Exploited in the wild: 0 Q1 2020: 1 CVE Q2 2020: 0 CVEs Q3 2020: 0 CVEs Q4 2020: 1 CVE Q1 2021: 0 CVEs Q2 2021: 0 CVEs Q3 2021: 1 CVE Q4 2021: 1 CVE Q1 2022: 1 CVE
Q1 20Q2 20Q3 20Q4 20Q1 21Q2 21Q3 21Q4 21Q1 22
5 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2022-24729 High 2022-03-16 Out of RASP scope No public exploit CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.
CVE-2021-41165 High 2021-11-17 No fix identified No public exploit CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.
CVE-2021-37695 High 2021-08-13 No exploit published No public exploit ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.
CVE-2020-27193 Medium 2020-11-12 Out of RASP scope No public exploit A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
CVE-2020-9281 Medium 2020-03-07 Out of RASP scope No public exploit A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).