CVE-2026-28343Disclosure(ckeditor / ckeditor5)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ckeditor5

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
ckeditor5

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-05: 2Mentions · 2026-03-06: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 103-0503-06
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-052
Disclosure1General1
2026-03-061
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28343 Cross-Site Scripting in CKEditor 5 General HTML Support Prior to ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28343 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    This short post alerts on CVE‑2026‑28343, a cross‑site scripting flaw in CKEditor 5's HTML support, without providing proof‑of‑concept, exploit code, or patch details.

    0000047
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28343 Intel Report: https://ift.tt/6L1QCAd

    Post summary

    The tweet alerts to CVE-2026-28343 and links to an intel report, but offers no additional technical, exploit, or patch information.

    0000033
    343 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28343 CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered i… https://www.cve.org/CVERecord?id=CVE-2026-28343

    Post summary

    The post announces a CVE-2026-28343 XSS vulnerability in CKEditor 5 affecting versions before 47.6.0, with no PoC, exploit, or patch details provided.

    0000080
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appckeditorckeditor5---

Explore more