GHSA-jrqm-vmqc-gm93 · Severity: medium · Ecosystem: npm — CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package
CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.
Conclusion & alert: CVE-2026-28343 is rated Low Risk (30.1/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.04%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-06 | — | 0.04% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.4 | 3.1 | MEDIUM |
|
3.1 | 2.7 | [email protected] |
| 6.1 | 3.1 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
GHSA-jrqm-vmqc-gm93 · Severity: medium · Ecosystem: npm — CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2026-28343 medium priority: Ubuntu including 4 source packages (ckeditor, ckeditor3, ldap-account-manager, request-tracker4), 31 status rows across 8 suites (bionic, focal, jammy, noble, questing, resolute, upstream, xenial): needs-triage 28, DNE 3. | https://ubuntu.com/security/CVE-2026-28343 |
| URL | Tags |
|---|---|
| https://github.com/ckeditor/ckeditor5/releases/tag/v29.0.0 | |
| https://github.com/ckeditor/ckeditor5/releases/tag/v47.6.0 | Release Notes |
| https://github.com/ckeditor/ckeditor5/security/advisories/GHSA-jrqm-vmqc-gm93 | Mitigation Vendor Advisory |