CVE Details
Basic Information
| Title | CKEditor5 Youtube – Moderately critical – Cross-site Scripting – SA-CONTRIB-2025-081 |
|---|---|
| Type | cve |
| Published | 2025-06-26T13:33:17.444Z |
| Last Seen |
Product Information
| Vendor | Drupal |
|---|---|
| Product | CKEditor5 Youtube |
| Version | 0.0.0 |
CVSS Information
| Base Score | 0.0 () |
|---|---|
| Attack Vector | |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A Cross-Site Scripting (XSS) vulnerability in the CKEditor5 Youtube plugin for Drupal allows attackers to inject malicious scripts. This can lead to unauthorized actions on behalf of users. The issue is fixed in versions 1.0.3 and above. |
|---|---|
| AI Severity | Medium |
| Vendor | Drupal Community |
| Product | CKEditor5 Youtube |
| Affected Version | 0.0.0 |
Affected Products
- Drupal CKEditor5 Youtube 0.0.0
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-79 |
| Bulletin Family |
References
Description
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Drupal CKEditor5 Youtube allows Cross-Site Scripting (XSS). This issue affects CKEditor5 Youtube: from 0.0.0 before 1.0.3.