CVE-2012-4000: Ckeditor Fckeditor

Medium severity, CVSS 4.3. EPSS: 4.3% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor 2.6.7 and earlier allows remote attackers to inject arbitrary web script or HTML via textinputs array parameters.

Affected products

  • Ckeditor Fckeditor: up to and including 2.6.7; version 0.8 only; version 0.8.5 only; version 0.9.0 only; version 0.9.1 only; version 0.9.2 only; …

Published 2012-07-12. Last modified 2026-06-16.