Description
Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10.; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.
Remediation
References
Related Vulnerabilities
WordPress Plugin GD Star Rating Multiple Vulnerabilities (1.9.22)
Drupal CVE-2018-7602 Vulnerability (CVE-2018-7602)
Microsoft SQL Server Other Vulnerability (CVE-2002-0154)
Liferay Portal Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2021-33320)
WordPress Plugin Lana Email Logger Cross-Site Scripting (1.0.2)