Description
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
Remediation
References
Related Vulnerabilities
Drupal Core 7.x Multiple Cross-Site Scripting Vulnerabilities (7.0 - 7.85)
VMware directory traversal and privilege escalation vulnerabilities
Serendipity Other Vulnerability (CVE-2009-4412)
WordPress Plugin FCChat Widget 'Upload.php' Arbitrary File Upload (2.2.13.1)
WordPress Plugin Ultimate WP Query Search Filter Cross-Site Scripting (1.0.10)