Cross-Site Scripting Vulnerability in CKEditor 5 by CKSource
CVE-2025-58064

2.3LOW

Key Information:

Vendor

Ckeditor

Status
Vendor
CVE Published:
3 September 2025

What is CVE-2025-58064?

CKEditor 5, a popular JavaScript rich-text editor, contains a Cross-Site Scripting (XSS) vulnerability in specific versions. This vulnerability could allow attackers to execute unauthorized JavaScript code through a malicious user action when certain editor configurations are met. Particularly, if the HTML embed plugin is enabled or if a custom plugin is present that allows editing with view RawElement enabled, the vulnerability can be exploited. Users are strongly advised to update to versions 45.2.2 and 46.0.3 of both ckeditor5 and ckeditor5-clipboard to mitigate risks associated with this issue.

Affected Version(s)

ckeditor5 >= 46.0.0, < 46.0.3 < 46.0.0, 46.0.3

ckeditor5 >= 44.2.0, < 45.2.2 < 44.2.0, 45.2.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-58064 : Cross-Site Scripting Vulnerability in CKEditor 5 by CKSource