Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2865 | CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration. This vulnerability only affects installations where the Block Toolbar plugin is enabled and either the General HTML Support (with a configuration that permits unsafe markup) or the HTML Embed plugin is also enabled. A fix for the problem is available in version 43.1.1. As a workaround, one may disable the block toolbar plugin. |
Github GHSA |
GHSA-rgg8-g5x8-wr9v | Cross-site scripting (XSS) in the clipboard package |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 01 Oct 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV4_0
|
Tue, 01 Oct 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ckeditor
Ckeditor ckeditor5 |
|
| CPEs | cpe:2.3:a:ckeditor:ckeditor5:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ckeditor
Ckeditor ckeditor5 |
Wed, 25 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Sep 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration. This vulnerability only affects installations where the Block Toolbar plugin is enabled and either the General HTML Support (with a configuration that permits unsafe markup) or the HTML Embed plugin is also enabled. A fix for the problem is available in version 43.1.1. As a workaround, one may disable the block toolbar plugin. | |
| Title | CKEditor 5 has Cross-site Scripting vulnerability in the clipboard package | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-01T21:20:44.633Z
Reserved: 2024-09-02T16:00:02.425Z
Link: CVE-2024-45613
Updated: 2024-09-25T14:23:45.824Z
Status : Modified
Published: 2024-09-25T14:15:05.303
Modified: 2024-10-01T22:15:02.757
Link: CVE-2024-45613
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA