4.3
CVSSv2

CVE-2014-5191

Published: 07/08/2014 Updated: 08/09/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Preview plugin prior to 4.4.3 in CKEditor allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ckeditor ckeditor 4.4.1

ckeditor ckeditor

ckeditor ckeditor 4.4.0

Vendor Advisories

Debian Bug report logs - #1015217 ckeditor3: CVE-2014-5191 CVE-2018-17960 CVE-2021-26271 CVE-2021-33829 CVE-2021-37695 CVE-2021-41165 CVE-2022-24728 CVE-2022-24729 Package: src:ckeditor3; Maintainer for src:ckeditor3 is Horde Maintainers <team+debian-horde-team@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inut ...
Debian Bug report logs - #760736 ckeditor: CVE-2014-5191 Package: ckeditor; Maintainer for ckeditor is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Source for ckeditor is src:ckeditor (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Sun, 7 Sep 2014 12:27:0 ...