Description
Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10.; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.
Remediation
References
Related Vulnerabilities
Joomla! Core 2.5.x Information Disclosure (2.5.0 - 2.5.4)
Opencart Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-28838)
Magento XML Injection (aka Blind XPath Injection) Vulnerability (CVE-2022-34253)
Mailman Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2006-4624)
WordPress Plugin WP-Live Chat by 3CX Cross-Site Scripting (7.0.06)