CVE-2022-24729

Regular expression Denial of Service in dialog plugin

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.


We have discovered 9,411 live websites that are affected by CVE-2022-24729.

Test my site




Affected Software

Product  CKEditor
Category Rich Text Editors
Vulnerable Domains9,411 live websites (79.94% of CKEditor install base)
Vulnerable Versions
  • from 0 before 4.18
Vulnerable Versions Count85 versions ( 85.86% of all versions)


Common Weakness Enumeration

CWE-400 Uncontrolled Resource Consumption



Details

  • Published - Mar 16, 2022
  • Updated - Aug 3, 2024

CVE-2022-24729 usage by Country

United States4,668 websites



France798 websites
Germany474 websites
Iran375 websites
Russia287 websites
Korea, South271 websites
Japan202 websites
GB163 websites
Poland142 websites
Singapore131 websites

CVE-2022-24729 usage by TLD

.com3,558 websites
.org1,029 websites
.net416 websites
.fr311 websites
.ru217 websites
.de165 websites
.com.br149 websites
.pl120 websites
.nl92 websites
.eu92 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-24729

Top websites that are affected by CVE-2022-24729. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.***.au Australia*,***
*****.net Ukraine**,***
****.***********.***.au Australia**,***
***.org United States**,***
****.***.au Australia**,***
********.org United States**,***
*******.***.ua United States**,***
***.ca United States**,***
***.***.au Australia**,***
****************.com United States**,***
See full domain list

FAQ

CVE-2022-24729 is Uncontrolled Resource Consumption in CKEditor
A total of 9,411 websites have been identified as vulnerable to CVE-2022-24729, discovered through global website indexing conducted by WebTechSurvey.
CKEditor is susceptible to CVE-2022-24729 vulnerability.
CKEditor versions before 4.18 are vulnerable to CVE-2022-24729.
Version 4.18 of CKEditor addresses the CVE-2022-24729 security vulnerability.