Cross-Site Scripting Vulnerability in CKEditor 5 by CKSource
CVE-2025-25299

2.3LOW

Key Information:

Vendor

Ckeditor

Status
Vendor
CVE Published:
20 February 2025

What is CVE-2025-25299?

A Cross-Site Scripting vulnerability exists within the CKEditor 5 real-time collaboration package, specifically affecting user markers that denote user positions in collaborative documents. This flaw allows for potential unauthorized JavaScript code execution under particular configurations of the editor and token endpoint. It is crucial to note that only installations with real-time collaborative editing enabled are vulnerable. CKSource has addressed this issue in version 44.2.1 and users are strongly encouraged to upgrade to secure their installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ckeditor5 @ckeditor/ckeditor5-real-time-collaboration: >= 41.3.0, < 44.2.1 < @ckeditor/ckeditor5-real-time-collaboration: 41.3.0, 44.2.1

ckeditor5 ckeditor5-premium-features: >= 42.0.0, < 44.2.1 < ckeditor5-premium-features: 42.0.0, 44.2.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.