Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19186 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 Youtube allows Cross-Site Scripting (XSS).This issue affects CKEditor5 Youtube: from 0.0.0 before 1.0.3. |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-081 |
|
Wed, 16 Jul 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gabderrahim
Gabderrahim ckeditor5 Youtube |
|
| CPEs | cpe:2.3:a:gabderrahim:ckeditor5_youtube:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Abderrahimghazali
Abderrahimghazali ckeditor5 Youtube |
Gabderrahim
Gabderrahim ckeditor5 Youtube |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Abderrahimghazali
Abderrahimghazali ckeditor5 Youtube |
|
| CPEs | cpe:2.3:a:abderrahimghazali:ckeditor5_youtube:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Abderrahimghazali
Abderrahimghazali ckeditor5 Youtube |
Thu, 26 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 26 Jun 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 Youtube allows Cross-Site Scripting (XSS).This issue affects CKEditor5 Youtube: from 0.0.0 before 1.0.3. | |
| Title | CKEditor5 Youtube - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-081 | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-06-26T19:41:06.446Z
Reserved: 2025-06-25T17:59:51.903Z
Link: CVE-2025-6674
Updated: 2025-06-26T17:44:36.252Z
Status : Analyzed
Published: 2025-06-26T14:15:34.047
Modified: 2025-07-16T16:39:26.070
Link: CVE-2025-6674
No data.
OpenCVE Enrichment
No data.
EUVD