In CiviCRM prior to 5.28.1 and CiviCRM ESR prior to 5.27.5 ESR, the CKEditor configuration form allows CSRF.
civicrm civicrm