CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.
We have discovered 9,411 live websites that are affected by CVE-2022-24729.
Product | ![]() |
Category | Rich Text Editors |
Vulnerable Domains | 9,411 live websites (79.94% of CKEditor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 85 versions ( 85.86% of all versions) |
![]() | 4,668 websites |
![]() | 798 websites |
![]() | 474 websites |
![]() | 375 websites |
![]() | 287 websites |
![]() | 271 websites |
![]() | 202 websites |
![]() | 163 websites |
![]() | 142 websites |
![]() | 131 websites |
.com | 3,558 websites |
.org | 1,029 websites |
.net | 416 websites |
.fr | 311 websites |
.ru | 217 websites |
.de | 165 websites |
.com.br | 149 websites |
.pl | 120 websites |
.nl | 92 websites |
.eu | 92 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********.***.au | ![]() | *,*** | |
*****.net | ![]() | **,*** | |
****.***********.***.au | ![]() | **,*** | |
***.org | ![]() | **,*** | |
****.***.au | ![]() | **,*** | |
********.org | ![]() | **,*** | |
*******.***.ua | ![]() | **,*** | |
***.ca | ![]() | **,*** | |
***.***.au | ![]() | **,*** | |
****************.com | ![]() | **,*** |
FAQ