CKEditor < 47.6.0 XSS

medium Nessus Plugin ID 301995

Synopsis

The remote web server may be affected by a cross site scripting vulnerability.

Description

The version of CKEditor included on the remote web host prior to 47.6.0. It may, therefore, be affected by a cross-site scripting (XSS) vulnerability.

- CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0. (CVE-2026-28343)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to CKEditor 47.6.0 or later.

See Also

http://www.nessus.org/u?c6c50d59

http://www.nessus.org/u?ba80c93b

Plugin Details

Severity: Medium

ID: 301995

File Name: cksource_ckeditor_47_6_0.nasl

Version: 1.1

Type: remote

Published: 3/12/2026

Updated: 3/12/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.8

CVSS v3

Risk Factor: Medium

Base Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CVSS Score Source: CVE-2026-28343

Vulnerability Information

CPE: cpe:/a:cksource:ckeditor

Required KB Items: installed_sw/CKSource CKEditor

Patch Publication Date: 3/5/2026

Vulnerability Publication Date: 3/5/2026

Reference Information

CVE: CVE-2026-28343

IAVA: 2026-A-0208