CVE-2026-28343

Source
https://cve.org/CVERecord?id=CVE-2026-28343
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28343.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-28343
Aliases
Downstream
Published
2026-03-05T19:42:58.372Z
Modified
2026-04-02T13:22:09.872539Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
Summary
CKEditor: Cross-site scripting (XSS) in the HTML Support package
Details

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28343.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/ckeditor/ckeditor5

Affected ranges

Type
GIT
Repo
https://github.com/ckeditor/ckeditor5
Events

Affected versions

v29.*
v29.0.0
v29.1.0
v29.2.0
v30.*
v30.0.0
v31.*
v31.0.0
v31.1.0
v32.*
v32.0.0
v33.*
v33.0.0
v34.*
v34.0.0
v34.1.0
v34.2.0
v35.*
v35.0.0
v35.0.1
v35.1.0
v35.2.0
v35.2.1
v35.3.0
v35.3.1
v35.3.2
v35.4.0
v36.*
v36.0.0
v36.0.1
v37.*
v37.0.0
v37.0.0-alpha.0
v37.0.0-alpha.1
v37.0.0-alpha.2
v37.0.0-alpha.3
v37.0.0-rc.0
v37.0.1
v37.1.0
v38.*
v38.0.0
v38.0.0-alpha.0
v38.0.0-rc.0
v38.0.0-rc.1
v38.0.1
v38.1.0
v38.1.1
v38.2.0-alpha.0
v38.2.0-alpha.1
v39.*
v39.0.0
v39.0.1
v39.0.2
v40.*
v40.0.0
v40.1.0
v40.2.0
v41.*
v41.0.0
v41.1.0
v41.2.0
v41.2.1
v41.3.0
v41.3.0-alpha.0
v41.3.0-alpha.1
v41.3.0-alpha.2
v41.3.0-alpha.3
v41.3.0-alpha.4
v41.3.1
v41.3.2
v41.4.0
v41.4.0-alpha.0
v41.4.1
v41.4.2
v42.*
v42.0.0
v42.0.1
v42.0.2
v43.*
v43.0.0
v43.1.0
v43.1.1
v43.2.0
v43.3.0
v43.3.1
v44.*
v44.0.0
v44.1.0
v44.2.0
v44.2.1
v44.3.0
v45.*
v45.0.0
v45.1.0
v45.2.0
v45.2.1
v45.2.2
v46.*
v46.0.0
v46.0.1
v46.0.2
v46.0.3
v46.1.0
v46.1.1
v47.*
v47.0.0
v47.1.0
v47.2.0
v47.3.0
v47.4.0
v47.5.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28343.json"