CVE-2021-32809Disclosure(ckeditor / application_express)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • application_express
  • banking_party_management
  • ckeditor
  • commerce_guided_search

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
application_expressbanking_party_managementckeditorcommerce_guided_searchcommerce_merchandisingdocumakerfedorafinancial_services_analytical_applications_infrastructurejd_edwards_enterpriseone_toolspeoplesoft_enterprise_peopletools

10 versions affected across 10 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-22: 1Technical Details · 2026-05-22: 105-22
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve
    Disclosure

    🟠 Flask-AppBuilder, Access Control Bypass, #CVE-2021-32809 (Medium) https://dailycve.com/flask-appbuilder-access-control-bypass-cve-2021-32809-medium/

    Post summary

    The tweet announces the discovery of a medium‑severity access control bypass in Flask‑AppBuilder (CVE‑2021‑32809), offering only basic vulnerability details without any PoC, exploit, or mitigation information.

    0000039
    207 followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
Appckeditorckeditor-node.js-
OSfedoraprojectfedora33--
OSfedoraprojectfedora34--
OSfedoraprojectfedora35--
Apporacleapplication_express---
Apporaclebanking_party_management2.7.0--
Apporaclecommerce_guided_search11.3.2--
Apporaclecommerce_merchandising11.3.2--
Apporacledocumaker12.6.3--
Apporacledocumaker12.6.4--
Apporaclefinancial_services_analytical_applications_infrastructure---
Apporaclejd_edwards_enterpriseone_tools---
Apporaclepeoplesoft_enterprise_peopletools8.57--
Apporaclepeoplesoft_enterprise_peopletools8.58--
Apporaclepeoplesoft_enterprise_peopletools8.59--

Explore more