浏览 27+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-28343 | CKEditor: Cross-site scripting (XSS) in the HTML Support package | ckeditor | ckeditor5 | Medium | 6.4 | 2026-03-05 19:42:58 | Deep Dive |
| CVE-2025-13980 | CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-118 | Drupal | CKEditor 5 Premium Features | - | - | 2026-01-28 20:01:17 | Deep Dive |
| CVE-2025-58064 | CKEditor is susceptible to Cross-Site Scripting (XSS) through its clipboard package | ckeditor | ckeditor5 | - | - | 2025-09-03 22:02:53 | Deep Dive |
| CVE-2025-25299 | Cross-site scripting (XSS) in the real-time collaboration package | ckeditor | ckeditor5 | 中危 | - | 2025-02-20 19:23:03 | Deep Dive |
| CVE-2024-13245 | CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009 | Drupal | CKEditor 4 LTS - WYSIWYG HTML editor | 中危 | - | 2025-01-09 18:51:18 | Deep Dive |
| CVE-2024-45613 | CKEditor 5 has Cross-site Scripting vulnerability in the clipboard package | ckeditor | ckeditor5 | - | - | 2024-09-25 13:27:04 | Deep Dive |
| CVE-2024-45400 | CKEditor Open Link plugin vulnerable to Cross-site Scripting | mlewand | ckeditor-plugin-openlink | Medium | 6.1 | 2024-09-05 23:23:33 | Deep Dive |
| CVE-2024-43411 | CKEditor4 has a low risk cross-site scripting (XSS) vulnerability from domain takeover | ckeditor | ckeditor4 | Low | 3.1 | 2024-08-21 15:17:24 | Deep Dive |
| CVE-2024-43407 | Code Snippet GeSHi plugin has reflected cross-site scripting (XSS) vulnerability | ckeditor | ckeditor4 | Medium | 6.1 | 2024-08-21 15:03:42 | Deep Dive |
| CVE-2024-37888 | The Open Link CKEditor plugin has a cross-site scripting (XSS) vulnerability in open link functionality | mlewand | ckeditor-plugin-openlink | Medium | 6.1 | 2024-06-14 17:17:27 | Deep Dive |
| CVE-2024-24816 | Cross-site scripting (XSS) vulnerability in samples with enabled the preview feature | ckeditor | ckeditor4 | Medium | 6.1 | 2024-02-07 16:58:25 | Deep Dive |
| CVE-2024-24815 | CKEditor4 Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detection | ckeditor | ckeditor4 | Medium | 6.1 | 2024-02-07 15:14:32 | Deep Dive |
| CVE-2023-4771 | Cross-Site Scripting vulnerability in CKSource CKEditor | CKSource | CKEditor | Medium | 6.1 | 2023-11-16 14:08:47 | Deep Dive |
| CVE-2023-37905 | Cross-site Scripting (XSS) in Source Mode of Editor in ckeditor-wordcount-plugin | w8tcha | CKEditor-WordCount-Plugin | Medium | 6.1 | 2023-07-21 19:35:50 | Deep Dive |
| CVE-2023-28439 | ckeditor4 plugins vulnerable to cross-site scripting caused by the editor instance destroying process | ckeditor | ckeditor4 | Medium | 4.7 | 2023-03-22 20:55:00 | Deep Dive |
| CVE-2023-22457 | org.xwiki.contrib:application-ckeditor-ui vulnerable to Remote Code Execution via Cross-Site Request Forgery | xwiki-contrib | application-ckeditor | Critical | 9.0 | 2023-01-04 14:24:40 | Deep Dive |
| CVE-2022-31175 | Cross-site scripting caused by the editor instance destroying process in ckeditor5 | ckeditor | ckeditor5 | Medium | 5.8 | 2022-08-03 19:05:13 | Deep Dive |
| CVE-2022-24729 | Regular expression Denial of Service in dialog plugin | ckeditor | ckeditor4 | Medium | 6.5 | 2022-03-16 00:00:00 | Deep Dive |
| CVE-2022-24728 | Cross-site Scripting in CKEditor4 | ckeditor | ckeditor4 | Medium | 5.4 | 2022-03-16 00:00:00 | Deep Dive |
| CVE-2021-41165 | HTML comments vulnerability allowing to execute JavaScript code | ckeditor | ckeditor4 | High | 8.2 | 2021-11-17 19:15:11 | Deep Dive |