{"id":"CVE-2023-37905","summary":"Cross-site Scripting (XSS) in Source Mode of Editor in ckeditor-wordcount-plugin","details":"ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the `ckeditor-wordcount-plugin` plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. This issue has been addressed in version 1.17.12 of the `ckeditor-wordcount-plugin` plugin and users are advised to upgrade. There are no known workarounds for this vulnerability.\n\n","aliases":["GHSA-q9w4-w667-qqj4"],"modified":"2026-07-08T06:36:36.450083403Z","published":"2023-07-21T19:35:49.656Z","related":["GHSA-m8fw-p3cr-6jqc","GHSA-q9w4-w667-qqj4"],"database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37905.json","unresolved_ranges":[{"extracted_events":[{"introduced":"10.0.0"},{"fixed":"10.4.39"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37905.json"},{"type":"ADVISORY","url":"https://github.com/TYPO3/typo3/security/advisories/GHSA-m8fw-p3cr-6jqc"},{"type":"ADVISORY","url":"https://github.com/w8tcha/CKEditor-WordCount-Plugin/security/advisories/GHSA-q9w4-w667-qqj4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37905"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-core-sa-2023-004"},{"type":"FIX","url":"https://github.com/w8tcha/CKEditor-WordCount-Plugin/commit/0f03b3e5b7c1409998a13aba3a95396e6fa349d8"},{"type":"FIX","url":"https://github.com/w8tcha/CKEditor-WordCount-Plugin/commit/a4b154bdf35b3465320136fcb078f196b437c2f1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/typo3/typo3","events":[{"introduced":"6a5e2d4097ef0a0e3ea955af93cf83810d6fa234"},{"fixed":"9eaf8f29875a17b5d48f296d83c1f58b24288b7c"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"11.0.0"},{"fixed":"11.5.30"}]}},{"type":"GIT","repo":"https://github.com/w8tcha/ckeditor-wordcount-plugin","events":[{"introduced":"0"},{"fixed":"a4b154bdf35b3465320136fcb078f196b437c2f1"},{"fixed":"0f03b3e5b7c1409998a13aba3a95396e6fa349d8"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.17.12"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:ckeditor-wordcount-plugin_project:ckeditor-wordcount-plugin:*:*:*:*:*:node.js:*:*"}}],"versions":["v11.5.29","v11.5.28","v11.5.27","v11.5.26","v11.5.25","v11.5.24","v11.5.23","v11.5.22","v11.5.21","v11.5.20","v11.5.19","v11.5.18","v11.5.17","v11.5.16","v11.5.15","v11.5.14","v11.5.13","v11.5.12","v11.5.11","v11.5.10","v11.5.9","v11.5.8","v11.5.7","v11.5.6","v11.5.5","v11.5.4","v11.5.3","v11.5.2","v11.5.1","v11.5.0","v11.4.0","v11.3.0","v11.2.0","v11.1.0","v11.0.0","v1.17.10","v1.17.9","v1.17.8","v1.17.6","v1.17.4","v1.17.3","v1.17.2","v1.17","v1.16","v0.13","v1.12","v1.10","v1.09","ceba9c9d46958d1f4c097532a521dc8ef45a5ef5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-37905.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}