Description
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
Remediation
References
Related Vulnerabilities
WordPress Plugin BetterDocs-Best Documentation & Knowledge Base Cross-Site Scripting (1.8.4)
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-1153)
Dotclear Other Vulnerability (CVE-2014-3782)
XWiki Insufficiently Protected Credentials Vulnerability (CVE-2022-41933)
WordPress Plugin WordPress Calls to Action Multiple Vulnerabilities (2.3.7)