ckeditor5
ckeditor- Product type
- Other
- Catalog vulnerabilities
- 8
Severity across 7 analyzed records
Verify to analyze this security profile
en
As of 09/18/2026, within CyStack's analyzed data, ckeditor5 has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of ckeditor5 and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-28343CKEditor: Cross-site scripting (XSS) in the HTML Support package | Exploitation statusNot known exploited | FixYes | Published03/05/2026 | SeverityMedium |
CVE-2025-61261 | Exploitation statusPublic exploit | FixNot confirmed | Published11/07/2025 | SeverityMedium |
CVE-2025-58064CKEditor is susceptible to Cross-Site Scripting (XSS) through its clipboard package | Exploitation statusNot known exploited | FixYes | Published09/03/2025 | SeverityLow |
CVE-2025-25299Cross-site scripting (XSS) in the real-time collaboration package | Exploitation statusNot known exploited | FixYes | Published02/20/2025 | SeverityLow |
CVE-2024-45613CKEditor 5 has Cross-site Scripting vulnerability in the clipboard package | Exploitation statusNot known exploited | FixNot confirmed | Published09/25/2024 | SeverityMedium |
CVE-2022-31175Cross-site scripting caused by the editor instance destroying process in ckeditor5 | Exploitation statusNot known exploited | FixYes | Published08/03/2022 | SeverityMedium |
CVE-2021-21391Regular expression Denial of Service in multiple packages | Exploitation statusNot confirmed | FixNot confirmed | Published04/29/2021 | SeverityMedium |
CVE-2021-21254Regular expression Denial of Service in Markdown plugin | Exploitation statusNot confirmed | FixNot confirmed | Published01/29/2021 | SeverityMedium |