{"schema_version":1,"title":"CKEditor vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in CKEditor: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-28343, was published on 4 March 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/ckeditor","json_url":"https://junglewise.ai/threats/vendors/ckeditor.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/ckeditor","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":0,"all_time":10,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":1},"latest":[{"cve":"CVE-2026-28343","cvss":3.1,"epss":0.0035,"slug":"cve-2026-28343-ckeditor-5-cross-site-scripting-in-html-support","title":"CKEditor 5 cross-site scripting in HTML Support","severity":"low","exploited":false,"published_at":"2026-03-04T18:49:32+00:00","url":"https://junglewise.ai/threats/cve-2026-28343-ckeditor-5-cross-site-scripting-in-html-support"},{"cve":"CVE-2025-58064","cvss":4,"epss":0.0042,"slug":"cve-2025-58064-ckeditor-5-cross-site-scripting-in-clipboard-package","title":"CKEditor 5 cross-site scripting in clipboard package","severity":"medium","exploited":false,"published_at":"2025-09-03T18:03:20+00:00","url":"https://junglewise.ai/threats/cve-2025-58064-ckeditor-5-cross-site-scripting-in-clipboard-package"},{"cve":"CVE-2025-25299","cvss":4,"epss":0.006,"slug":"cve-2025-25299-ckeditor-5-cross-site-scripting-in-real-time-collaboration","title":"CKEditor 5 cross-site scripting in real-time collaboration","severity":"medium","exploited":false,"published_at":"2025-02-20T20:16:31+00:00","url":"https://junglewise.ai/threats/cve-2025-25299-ckeditor-5-cross-site-scripting-in-real-time-collaboration"},{"cve":"CVE-2021-26271","cvss":3.1,"epss":0.0197,"slug":"cve-2021-26271-ckeditor-4-regular-expression-denial-of-service","title":"CKEditor 4 regular expression denial of service","severity":"low","exploited":false,"published_at":"2022-05-24T17:40:21+00:00","url":"https://junglewise.ai/threats/cve-2021-26271-ckeditor-4-regular-expression-denial-of-service"},{"cve":"CVE-2020-27193","cvss":3.1,"epss":0.0203,"slug":"cve-2020-27193-ckeditor4-cross-site-scripting-in-color-dialog","title":"CKEditor4 cross-site scripting in Color Dialog","severity":"low","exploited":false,"published_at":"2022-05-24T17:34:01+00:00","url":"https://junglewise.ai/threats/cve-2020-27193-ckeditor4-cross-site-scripting-in-color-dialog"},{"cve":"CVE-2021-26272","cvss":3.1,"epss":0.0222,"slug":"cve-2021-26272-ckeditor-4-redos-in-autolink-plugin","title":"CKEditor 4 ReDoS in Autolink plugin","severity":"low","exploited":false,"published_at":"2021-10-13T15:34:09+00:00","url":"https://junglewise.ai/threats/cve-2021-26272-ckeditor-4-redos-in-autolink-plugin"},{"cve":"CVE-2021-33829","cvss":3.1,"epss":0.0319,"slug":"cve-2021-33829-ckeditor-4-cross-site-scripting-in-html-data-processor","title":"DRUPAL-CORE-2021-003 - **Update: 2021-06-11: Added identifier** Drupal core uses the third-party CKEditor library. This library has an error in par","severity":"low","exploited":false,"published_at":"2021-05-26T18:33:55+00:00","url":"https://junglewise.ai/threats/cve-2021-33829-ckeditor-4-cross-site-scripting-in-html-data-processor"},{"cve":"CVE-2020-9281","cvss":3.1,"epss":0.0431,"slug":"cve-2020-9281-ckeditor-4-cross-site-scripting-in-html-data-processor","title":"CKEditor 4 cross-site scripting in HTML Data Processor","severity":"low","exploited":false,"published_at":"2021-05-07T16:32:17+00:00","url":"https://junglewise.ai/threats/cve-2020-9281-ckeditor-4-cross-site-scripting-in-html-data-processor"},{"cve":"CVE-2021-21391","cvss":3.1,"slug":"cve-2021-21391-ckeditor-5-redos-in-multiple-packages","title":"CKEditor 5 ReDoS in multiple packages","severity":"low","exploited":false,"published_at":"2021-04-06T17:28:41+00:00","url":"https://junglewise.ai/threats/cve-2021-21391-ckeditor-5-redos-in-multiple-packages"},{"cve":"CVE-2018-11093","cvss":3.1,"epss":0.0102,"slug":"cve-2018-11093-ckeditor-ckeditor5-link-cross-site-scripting-in-link-preview","title":"CKEditor ckeditor5-link cross-site scripting in link preview","severity":"low","exploited":false,"published_at":"2018-05-23T20:37:46+00:00","url":"https://junglewise.ai/threats/cve-2018-11093-ckeditor-ckeditor5-link-cross-site-scripting-in-link-preview"}],"vendor":{"hub":true,"name":"CKEditor","slug":"ckeditor","homepage":"https://ckeditor.com","description":"CKEditor is a web-based WYSIWYG rich text editor for content creation and editing in web applications.","url":"https://junglewise.ai/threats/vendors/ckeditor"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2025-25299","cvss":4,"epss":0.006,"slug":"cve-2025-25299-ckeditor-5-cross-site-scripting-in-real-time-collaboration","title":"CKEditor 5 cross-site scripting in real-time collaboration","severity":"medium","exploited":false,"published_at":"2025-02-20T20:16:31+00:00","url":"https://junglewise.ai/threats/cve-2025-25299-ckeditor-5-cross-site-scripting-in-real-time-collaboration"},{"cve":"CVE-2025-58064","cvss":4,"epss":0.0042,"slug":"cve-2025-58064-ckeditor-5-cross-site-scripting-in-clipboard-package","title":"CKEditor 5 cross-site scripting in clipboard package","severity":"medium","exploited":false,"published_at":"2025-09-03T18:03:20+00:00","url":"https://junglewise.ai/threats/cve-2025-58064-ckeditor-5-cross-site-scripting-in-clipboard-package"},{"cve":"CVE-2020-9281","cvss":3.1,"epss":0.0431,"slug":"cve-2020-9281-ckeditor-4-cross-site-scripting-in-html-data-processor","title":"CKEditor 4 cross-site scripting in HTML Data Processor","severity":"low","exploited":false,"published_at":"2021-05-07T16:32:17+00:00","url":"https://junglewise.ai/threats/cve-2020-9281-ckeditor-4-cross-site-scripting-in-html-data-processor"},{"cve":"CVE-2021-33829","cvss":3.1,"epss":0.0319,"slug":"cve-2021-33829-ckeditor-4-cross-site-scripting-in-html-data-processor","title":"DRUPAL-CORE-2021-003 - **Update: 2021-06-11: Added identifier** Drupal core uses the third-party CKEditor library. This library has an error in par","severity":"low","exploited":false,"published_at":"2021-05-26T18:33:55+00:00","url":"https://junglewise.ai/threats/cve-2021-33829-ckeditor-4-cross-site-scripting-in-html-data-processor"},{"cve":"CVE-2021-26272","cvss":3.1,"epss":0.0222,"slug":"cve-2021-26272-ckeditor-4-redos-in-autolink-plugin","title":"CKEditor 4 ReDoS in Autolink plugin","severity":"low","exploited":false,"published_at":"2021-10-13T15:34:09+00:00","url":"https://junglewise.ai/threats/cve-2021-26272-ckeditor-4-redos-in-autolink-plugin"},{"cve":"CVE-2020-27193","cvss":3.1,"epss":0.0203,"slug":"cve-2020-27193-ckeditor4-cross-site-scripting-in-color-dialog","title":"CKEditor4 cross-site scripting in Color Dialog","severity":"low","exploited":false,"published_at":"2022-05-24T17:34:01+00:00","url":"https://junglewise.ai/threats/cve-2020-27193-ckeditor4-cross-site-scripting-in-color-dialog"},{"cve":"CVE-2021-26271","cvss":3.1,"epss":0.0197,"slug":"cve-2021-26271-ckeditor-4-regular-expression-denial-of-service","title":"CKEditor 4 regular expression denial of service","severity":"low","exploited":false,"published_at":"2022-05-24T17:40:21+00:00","url":"https://junglewise.ai/threats/cve-2021-26271-ckeditor-4-regular-expression-denial-of-service"},{"cve":"CVE-2018-11093","cvss":3.1,"epss":0.0102,"slug":"cve-2018-11093-ckeditor-ckeditor5-link-cross-site-scripting-in-link-preview","title":"CKEditor ckeditor5-link cross-site scripting in link preview","severity":"low","exploited":false,"published_at":"2018-05-23T20:37:46+00:00","url":"https://junglewise.ai/threats/cve-2018-11093-ckeditor-ckeditor5-link-cross-site-scripting-in-link-preview"},{"cve":"CVE-2026-28343","cvss":3.1,"epss":0.0035,"slug":"cve-2026-28343-ckeditor-5-cross-site-scripting-in-html-support","title":"CKEditor 5 cross-site scripting in HTML Support","severity":"low","exploited":false,"published_at":"2026-03-04T18:49:32+00:00","url":"https://junglewise.ai/threats/cve-2026-28343-ckeditor-5-cross-site-scripting-in-html-support"},{"cve":"CVE-2021-21391","cvss":3.1,"slug":"cve-2021-21391-ckeditor-5-redos-in-multiple-packages","title":"CKEditor 5 ReDoS in multiple packages","severity":"low","exploited":false,"published_at":"2021-04-06T17:28:41+00:00","url":"https://junglewise.ai/threats/cve-2021-21391-ckeditor-5-redos-in-multiple-packages"}],"generated_at":"2026-09-26T18:07:00.158435+00:00","technologies":[{"name":"CKEditor 4","slug":"ckeditor-4","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/ckeditor-4"},{"name":"CKEditor 5","slug":"ckeditor-5","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/ckeditor-5"}]}