CVE-2021-32809

Arbitrary HTML injection vulnerability in ckeditor

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.


We have discovered 8,247 live websites that are affected by CVE-2021-32809.

Test my site




Affected Software

Product  CKEditor
Category Rich Text Editors
Vulnerable Domains8,247 live websites (70.06% of CKEditor install base)
Vulnerable Versions
  • from 4.5.2 before 4.16.2
Vulnerable Versions Count44 versions ( 44.44% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Aug 13, 2021
  • Updated - Aug 3, 2024

CVE-2021-32809 usage by Country

United States4,105 websites



France630 websites
Germany415 websites
Iran373 websites
Korea, South264 websites
Russia217 websites
Japan190 websites
GB143 websites
Poland133 websites
Singapore123 websites

CVE-2021-32809 usage by TLD

.com3,038 websites
.org973 websites
.net391 websites
.fr181 websites
.ru177 websites
.de149 websites
.com.br113 websites
.pl111 websites
.eu91 websites
.cz81 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-32809

Top websites that are affected by CVE-2021-32809. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.***.au Australia*,***
*****.net Ukraine**,***
****.***********.***.au Australia**,***
***.org United States**,***
****.***.au Australia**,***
********.org United States**,***
*******.***.ua United States**,***
***.ca United States**,***
***.***.au Australia**,***
****************.com United States**,***
See full domain list

FAQ

CVE-2021-32809 is Improper Control of Generation of Code ('Code Injection') in CKEditor
A total of 8,247 websites have been identified as vulnerable to CVE-2021-32809, discovered through global website indexing conducted by WebTechSurvey.
CKEditor is susceptible to CVE-2021-32809 vulnerability.
CKEditor versions before 4.16.2 are vulnerable to CVE-2021-32809.
Version 4.16.2 of CKEditor addresses the CVE-2021-32809 security vulnerability.