Drupal core's built-in CKEditor image caption functionality is vulnerable to XSS.
{ "constraint": ">= 8.0.0 <8.8.10" }
{ "constraint": ">= 8.9.0 <8.9.6" }
{ "constraint": ">=9.0.0 <9.0.6" }
">= 8.0.0 <8.8.10 || >= 8.9.0 <8.9.6 || >=9.0.0 <9.0.6"