Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2018-0193 | Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element. |
![]() |
GHSA-gvpx-9459-w3mj | Cross-Site Scripting in @ckeditor/ckeditor5-link |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T07:54:36.540Z
Reserved: 2018-05-14T00:00:00
Link: CVE-2018-11093

No data.

Status : Modified
Published: 2018-05-22T18:29:00.233
Modified: 2024-11-21T03:42:39.803
Link: CVE-2018-11093

No data.

No data.