Cross-Site Scripting Vulnerability in CKEditor 5 by CKSource
CVE-2025-58064
2.3LOW
What is CVE-2025-58064?
CKEditor 5, a popular JavaScript rich-text editor, contains a Cross-Site Scripting (XSS) vulnerability in specific versions. This vulnerability could allow attackers to execute unauthorized JavaScript code through a malicious user action when certain editor configurations are met. Particularly, if the HTML embed plugin is enabled or if a custom plugin is present that allows editing with view RawElement enabled, the vulnerability can be exploited. Users are strongly advised to update to versions 45.2.2 and 46.0.3 of both ckeditor5 and ckeditor5-clipboard to mitigate risks associated with this issue.
Affected Version(s)
ckeditor5 >= 46.0.0, < 46.0.3 < 46.0.0, 46.0.3
ckeditor5 >= 44.2.0, < 45.2.2 < 44.2.0, 45.2.2