CVE-2025-6674: Gabderrahim CKEDITOR5 YouTube
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 Youtube allows Cross-Site Scripting (XSS).This issue affects CKEditor5 Youtube: from 0.0.0 before 1.0.3.
Affected products
- Gabderrahim CKEDITOR5 YouTube: before 1.0.4 (fixed in 1.0.4)
Published 2025-06-26. Last modified 2026-06-17.