Description

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.

INFO

Published Date :

2026-03-05T19:42:58.372Z

Last Modified :

2026-03-19T18:45:43.135Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-28343 vulnerability.

Vendors Products
Ckeditor
  • Ckeditor5
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact