Description
Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10.; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.
Remediation
References
Related Vulnerabilities
Python Uncontrolled Resource Consumption Vulnerability (CVE-2025-13837)
Moodle Use of GET Request Method With Sensitive Query Strings Vulnerability (CVE-2025-3637)
PHP Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability (CVE-2004-0594)
WordPress Plugin Blogomatic Cross-Site Scripting (1.0)
Jenkins Missing Authorization Vulnerability (CVE-2025-59474)