{"schema_version":1,"title":"CKEditor 4 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 5 vulnerabilities in CKEditor 4: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2021-26271, was published on 24 May 2022.","url":"https://junglewise.ai/threats/technologies/ckeditor-4","json_url":"https://junglewise.ai/threats/technologies/ckeditor-4.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/ckeditor-4","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":5,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cve":"CVE-2021-26271","cvss":3.1,"epss":0.0197,"slug":"cve-2021-26271-ckeditor-4-regular-expression-denial-of-service","title":"CKEditor 4 regular expression denial of service","severity":"low","exploited":false,"published_at":"2022-05-24T17:40:21+00:00","url":"https://junglewise.ai/threats/cve-2021-26271-ckeditor-4-regular-expression-denial-of-service"},{"cve":"CVE-2020-27193","cvss":3.1,"epss":0.0203,"slug":"cve-2020-27193-ckeditor4-cross-site-scripting-in-color-dialog","title":"CKEditor4 cross-site scripting in Color Dialog","severity":"low","exploited":false,"published_at":"2022-05-24T17:34:01+00:00","url":"https://junglewise.ai/threats/cve-2020-27193-ckeditor4-cross-site-scripting-in-color-dialog"},{"cve":"CVE-2021-26272","cvss":3.1,"epss":0.0222,"slug":"cve-2021-26272-ckeditor-4-redos-in-autolink-plugin","title":"CKEditor 4 ReDoS in Autolink plugin","severity":"low","exploited":false,"published_at":"2021-10-13T15:34:09+00:00","url":"https://junglewise.ai/threats/cve-2021-26272-ckeditor-4-redos-in-autolink-plugin"},{"cve":"CVE-2021-33829","cvss":3.1,"epss":0.0319,"slug":"cve-2021-33829-ckeditor-4-cross-site-scripting-in-html-data-processor","title":"CKEditor 4 cross-site scripting in HTML Data Processor","severity":"low","exploited":false,"published_at":"2021-06-21T17:16:42+00:00","url":"https://junglewise.ai/threats/cve-2021-33829-ckeditor-4-cross-site-scripting-in-html-data-processor"},{"cve":"CVE-2020-9281","cvss":3.1,"epss":0.0431,"slug":"cve-2020-9281-ckeditor-4-cross-site-scripting-in-html-data-processor","title":"CKEditor 4 cross-site scripting in HTML Data Processor","severity":"low","exploited":false,"published_at":"2021-05-07T16:32:17+00:00","url":"https://junglewise.ai/threats/cve-2020-9281-ckeditor-4-cross-site-scripting-in-html-data-processor"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"CKEditor 5","slug":"ckeditor-5","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/ckeditor-5"}],"technology":{"hub":true,"name":"CKEditor 4","slug":"ckeditor-4","vendor":{"name":"CKEditor","slug":"ckeditor","url":"https://junglewise.ai/threats/vendors/ckeditor"},"aliases":[],"category":"library","homepage":"https://ckeditor.com/","description":"A WYSIWYG rich text editor for web applications.","url":"https://junglewise.ai/threats/technologies/ckeditor-4"},"most_severe":[{"cve":"CVE-2020-9281","cvss":3.1,"epss":0.0431,"slug":"cve-2020-9281-ckeditor-4-cross-site-scripting-in-html-data-processor","title":"CKEditor 4 cross-site scripting in HTML Data Processor","severity":"low","exploited":false,"published_at":"2021-05-07T16:32:17+00:00","url":"https://junglewise.ai/threats/cve-2020-9281-ckeditor-4-cross-site-scripting-in-html-data-processor"},{"cve":"CVE-2021-33829","cvss":3.1,"epss":0.0319,"slug":"cve-2021-33829-ckeditor-4-cross-site-scripting-in-html-data-processor","title":"CKEditor 4 cross-site scripting in HTML Data Processor","severity":"low","exploited":false,"published_at":"2021-06-21T17:16:42+00:00","url":"https://junglewise.ai/threats/cve-2021-33829-ckeditor-4-cross-site-scripting-in-html-data-processor"},{"cve":"CVE-2021-26272","cvss":3.1,"epss":0.0222,"slug":"cve-2021-26272-ckeditor-4-redos-in-autolink-plugin","title":"CKEditor 4 ReDoS in Autolink plugin","severity":"low","exploited":false,"published_at":"2021-10-13T15:34:09+00:00","url":"https://junglewise.ai/threats/cve-2021-26272-ckeditor-4-redos-in-autolink-plugin"},{"cve":"CVE-2020-27193","cvss":3.1,"epss":0.0203,"slug":"cve-2020-27193-ckeditor4-cross-site-scripting-in-color-dialog","title":"CKEditor4 cross-site scripting in Color Dialog","severity":"low","exploited":false,"published_at":"2022-05-24T17:34:01+00:00","url":"https://junglewise.ai/threats/cve-2020-27193-ckeditor4-cross-site-scripting-in-color-dialog"},{"cve":"CVE-2021-26271","cvss":3.1,"epss":0.0197,"slug":"cve-2021-26271-ckeditor-4-regular-expression-denial-of-service","title":"CKEditor 4 regular expression denial of service","severity":"low","exploited":false,"published_at":"2022-05-24T17:40:21+00:00","url":"https://junglewise.ai/threats/cve-2021-26271-ckeditor-4-regular-expression-denial-of-service"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}