CVE-2025-6674: Gabderrahim CKEDITOR5 YouTube

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 Youtube allows Cross-Site Scripting (XSS).This issue affects CKEditor5 Youtube: from 0.0.0 before 1.0.3.

Affected products

  • Gabderrahim CKEDITOR5 YouTube: before 1.0.4 (fixed in 1.0.4)

Published 2025-06-26. Last modified 2026-06-17.