Description
CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.
INFO
Published Date :
2026-03-05T19:42:58.372Z
Last Modified :
2026-03-19T18:45:43.135Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-28343 vulnerability.
| Vendors | Products |
|---|---|
| Ckeditor |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-28343.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact