CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.
We have discovered 9,152 live websites that are affected by CVE-2021-41165.
Product | ![]() |
Category | Rich Text Editors |
Vulnerable Domains | 9,152 live websites (77.74% of CKEditor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 81 versions ( 81.82% of all versions) |
![]() | 4,481 websites |
![]() | 791 websites |
![]() | 464 websites |
![]() | 375 websites |
![]() | 286 websites |
![]() | 270 websites |
![]() | 201 websites |
![]() | 161 websites |
![]() | 137 websites |
![]() | 129 websites |
.com | 3,391 websites |
.org | 1,016 websites |
.net | 411 websites |
.fr | 311 websites |
.ru | 216 websites |
.de | 162 websites |
.com.br | 135 websites |
.pl | 115 websites |
.eu | 91 websites |
.nl | 91 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********.***.au | ![]() | *,*** | |
*****.net | ![]() | **,*** | |
****.***********.***.au | ![]() | **,*** | |
***.org | ![]() | **,*** | |
****.***.au | ![]() | **,*** | |
********.org | ![]() | **,*** | |
*******.***.ua | ![]() | **,*** | |
***.ca | ![]() | **,*** | |
***.***.au | ![]() | **,*** | |
****************.com | ![]() | **,*** |
FAQ