Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-33829

A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 77.3%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
References
Products affected by CVE-2021-33829
  • Ckeditor » Ckeditor » Version: 4.14.0
    cpe:2.3:a:ckeditor:ckeditor:4.14.0
  • Ckeditor » Ckeditor » Version: 4.14.1
    cpe:2.3:a:ckeditor:ckeditor:4.14.1
  • Ckeditor » Ckeditor » Version: 4.15.0
    cpe:2.3:a:ckeditor:ckeditor:4.15.0
  • Ckeditor » Ckeditor » Version: 4.15.1
    cpe:2.3:a:ckeditor:ckeditor:4.15.1
  • Ckeditor » Ckeditor » Version: 4.16
    cpe:2.3:a:ckeditor:ckeditor:4.16
  • Ckeditor » Ckeditor » Version: 4.16.0
    cpe:2.3:a:ckeditor:ckeditor:4.16.0
  • Drupal » Drupal » Version: 8.9.0
    cpe:2.3:a:drupal:drupal:8.9.0
  • Drupal » Drupal » Version: 8.9.1
    cpe:2.3:a:drupal:drupal:8.9.1
  • Drupal » Drupal » Version: 8.9.10
    cpe:2.3:a:drupal:drupal:8.9.10
  • Drupal » Drupal » Version: 8.9.11
    cpe:2.3:a:drupal:drupal:8.9.11
  • Drupal » Drupal » Version: 8.9.12
    cpe:2.3:a:drupal:drupal:8.9.12
  • Drupal » Drupal » Version: 8.9.13
    cpe:2.3:a:drupal:drupal:8.9.13
  • Drupal » Drupal » Version: 8.9.14
    cpe:2.3:a:drupal:drupal:8.9.14
  • Drupal » Drupal » Version: 8.9.15
    cpe:2.3:a:drupal:drupal:8.9.15
  • Drupal » Drupal » Version: 8.9.2
    cpe:2.3:a:drupal:drupal:8.9.2
  • Drupal » Drupal » Version: 8.9.3
    cpe:2.3:a:drupal:drupal:8.9.3
  • Drupal » Drupal » Version: 8.9.4
    cpe:2.3:a:drupal:drupal:8.9.4
  • Drupal » Drupal » Version: 8.9.5
    cpe:2.3:a:drupal:drupal:8.9.5
  • Drupal » Drupal » Version: 8.9.6
    cpe:2.3:a:drupal:drupal:8.9.6
  • Drupal » Drupal » Version: 8.9.7
    cpe:2.3:a:drupal:drupal:8.9.7
  • Drupal » Drupal » Version: 8.9.8
    cpe:2.3:a:drupal:drupal:8.9.8
  • Drupal » Drupal » Version: 8.9.9
    cpe:2.3:a:drupal:drupal:8.9.9
  • Drupal » Drupal » Version: 9.0.0
    cpe:2.3:a:drupal:drupal:9.0.0
  • Drupal » Drupal » Version: 9.0.1
    cpe:2.3:a:drupal:drupal:9.0.1
  • Drupal » Drupal » Version: 9.0.10
    cpe:2.3:a:drupal:drupal:9.0.10
  • Drupal » Drupal » Version: 9.0.11
    cpe:2.3:a:drupal:drupal:9.0.11
  • Drupal » Drupal » Version: 9.0.12
    cpe:2.3:a:drupal:drupal:9.0.12
  • Drupal » Drupal » Version: 9.0.13
    cpe:2.3:a:drupal:drupal:9.0.13
  • Drupal » Drupal » Version: 9.0.2
    cpe:2.3:a:drupal:drupal:9.0.2
  • Drupal » Drupal » Version: 9.0.3
    cpe:2.3:a:drupal:drupal:9.0.3
  • Drupal » Drupal » Version: 9.0.4
    cpe:2.3:a:drupal:drupal:9.0.4
  • Drupal » Drupal » Version: 9.0.5
    cpe:2.3:a:drupal:drupal:9.0.5
  • Drupal » Drupal » Version: 9.0.6
    cpe:2.3:a:drupal:drupal:9.0.6
  • Drupal » Drupal » Version: 9.0.7
    cpe:2.3:a:drupal:drupal:9.0.7
  • Drupal » Drupal » Version: 9.0.8
    cpe:2.3:a:drupal:drupal:9.0.8
  • Drupal » Drupal » Version: 9.0.9
    cpe:2.3:a:drupal:drupal:9.0.9
  • Drupal » Drupal » Version: 9.1.0
    cpe:2.3:a:drupal:drupal:9.1.0
  • Drupal » Drupal » Version: 9.1.1
    cpe:2.3:a:drupal:drupal:9.1.1
  • Drupal » Drupal » Version: 9.1.2
    cpe:2.3:a:drupal:drupal:9.1.2
  • Drupal » Drupal » Version: 9.1.3
    cpe:2.3:a:drupal:drupal:9.1.3
  • Drupal » Drupal » Version: 9.1.4
    cpe:2.3:a:drupal:drupal:9.1.4
  • Drupal » Drupal » Version: 9.1.5
    cpe:2.3:a:drupal:drupal:9.1.5
  • Drupal » Drupal » Version: 9.1.6
    cpe:2.3:a:drupal:drupal:9.1.6
  • Drupal » Drupal » Version: 9.1.7
    cpe:2.3:a:drupal:drupal:9.1.7
  • Drupal » Drupal » Version: 9.1.8
    cpe:2.3:a:drupal:drupal:9.1.8
  • Debian » Debian Linux » Version: 9.0
    cpe:2.3:o:debian:debian_linux:9.0
  • Fedoraproject » Fedora » Version: 33
    cpe:2.3:o:fedoraproject:fedora:33
  • Fedoraproject » Fedora » Version: 34
    cpe:2.3:o:fedoraproject:fedora:34
  • Fedoraproject » Fedora » Version: 35
    cpe:2.3:o:fedoraproject:fedora:35


Contact Us

Shodan ® - All rights reserved