CVE-2018-11093: Ckeditor 5-Link

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.

Affected products

  • Ckeditor Ckeditor 5-Link: before 10.0.1 (fixed in 10.0.1)

Published 2018-05-22. Last modified 2026-06-17.