← Vulnerability feed

Vulnerability record · CVE-2021-41165 · published 17 November 2021

CVE-2021-41165: Ckeditor cross-site scripting vulnerability

Ckeditor · Ckeditor

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

5.4 CVSS 3.1 Medium EPSS 1.6% · top 25.6% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41165 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-9082Drupal core SQL injection in unauthenticated request pathDrupal core contains a SQL injection flaw (CWE-89) caused by improper neutralization of special elements in SQL commands. It affects multiple core br…KEVEPSS 16%analysed9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2019-2725Oracle WebLogic Server Web Services deserialization RCEOracle WebLogic Server's Web Services subcomponent contains an injection flaw (CWE-74) that allows unauthenticated remote code execution over HTTP. I…KEVEPSS 100%analysed9.8CVE-2018-7602Drupal Core Remote Code Execution via Multiple SubsystemsCVE-2018-7602 is a remote code execution flaw in multiple subsystems of Drupal 7.x and 8.x, related to SA-CORE-2018-002. It allows an attacker to com…KEVEPSS 99%analysed9.8CVE-2018-7600Drupal Core input validation flaw enables remote code executionDrupal core before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 fails to properly validate input across multiple subsystems, al…KEVEPSS 100%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed8.8CVE-2024-20953Oracle Agile PLM Export deserialization allows takeoverOracle Agile Product Lifecycle Management 9.3.6 contains a deserialization flaw in the Export component. A low-privileged attacker with network acces…KEVEPSS 3.9%analysed8.8CVE-2020-13671Drupal core filename sanitization flaw allows uploaded files to execute as PHPDrupal core fails to properly sanitize certain filenames on uploaded files, so files can be interpreted with the wrong extension and served as the wr…KEVEPSS 35%analysed

Source: NIST National Vulnerability Database (record CVE-2021-41165), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.