ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.
We have discovered 8,247 live websites that are affected by CVE-2021-32809.
Product | ![]() |
Category | Rich Text Editors |
Vulnerable Domains | 8,247 live websites (70.06% of CKEditor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 44 versions ( 44.44% of all versions) |
![]() | 4,105 websites |
![]() | 630 websites |
![]() | 415 websites |
![]() | 373 websites |
![]() | 264 websites |
![]() | 217 websites |
![]() | 190 websites |
![]() | 143 websites |
![]() | 133 websites |
![]() | 123 websites |
.com | 3,038 websites |
.org | 973 websites |
.net | 391 websites |
.fr | 181 websites |
.ru | 177 websites |
.de | 149 websites |
.com.br | 113 websites |
.pl | 111 websites |
.eu | 91 websites |
.cz | 81 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********.***.au | ![]() | *,*** | |
*****.net | ![]() | **,*** | |
****.***********.***.au | ![]() | **,*** | |
***.org | ![]() | **,*** | |
****.***.au | ![]() | **,*** | |
********.org | ![]() | **,*** | |
*******.***.ua | ![]() | **,*** | |
***.ca | ![]() | **,*** | |
***.***.au | ![]() | **,*** | |
****************.com | ![]() | **,*** |
FAQ