Description
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Remediation
References
Related Vulnerabilities
WordPress Plugin Another WordPress Classifieds Unspecified Vulnerability (1.8.9.4)
WordPress Plugin oQey Gallery 'tbpv_domain' Parameter Cross-Site Scripting (0.2)
MySQL CVE-2021-35591 Vulnerability (CVE-2021-35591)
WordPress Plugin Live Chat Unlimited Cross-Site Scripting (2.8.3)
Microsoft SQL Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-5090)