CVE-2026-28343 MEDIUM

CVE-2026-28343: CKEditor: Cross-site scripting (XSS) in the HTML Support package

Vendor Ckeditor
Product ckeditor5
Weakness CWE-79 · XSS
Published March 5, 2026
Last update March 19, 2026

CVSS base score

6.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.

Key dates

02Disclosure timeline

March 5, 2026 CVE published
March 19, 2026 Record updated