A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
{
"versions": [
{
"introduced": "4.0"
},
{
"fixed": "4.14"
}
]
}{
"versions": [
{
"introduced": "8.7.0"
},
{
"fixed": "8.7.12"
},
{
"introduced": "8.8.0"
},
{
"fixed": "8.8.4"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.5"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.6"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "30"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "31"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "20.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.2.5.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.56"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.57"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.58"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "21.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.1.1.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.6.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.7.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.10.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.12.0"
}
]
},
{
"events": [
{
"introduced": "2.3.0"
},
{
"last_affected": "2.4.0"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-9281.json"