Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26646 | CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package |
Github GHSA |
GHSA-x9gp-vjh6-3wv6 | CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package |
Thu, 04 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ckeditor
Ckeditor ckeditor5 |
|
| Vendors & Products |
Ckeditor
Ckeditor ckeditor5 |
Wed, 03 Sep 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 44.2.0 through 45.2.1 contain a Cross-Site Scripting (XSS) vulnerability. Ability to exploit could be triggered by a specific user action (leading to unauthorized JavaScript code execution) if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration. This vulnerability affects installations where the editor configuration meets one of the following criteria: the HTML embed plugin is enabled, or there is a custom plugin introducing an editable element where view RawElement is enabled. This issue is fixed in versions 45.2.2 and 46.0.3 of both ckeditor5 and ckeditor5-clipboard. | |
| Title | CKEditor is susceptible to Cross-Site Scripting (XSS) through its clipboard package | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-04T20:03:46.927Z
Reserved: 2025-08-22T14:30:32.222Z
Link: CVE-2025-58064
Updated: 2025-09-04T20:03:43.916Z
Status : Deferred
Published: 2025-09-04T10:42:32.343
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-58064
No data.
OpenCVE Enrichment
Updated: 2025-09-04T13:12:22Z
EUVD
Github GHSA