← Back to CVE List

CVE-2021-33829

Published: 2021-06-09T12:15Z
Last Modified: 2024-11-21T06:09Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt