{"id":"CVE-2023-37905","aliases":["GHSA-q9w4-w667-qqj4"],"url":"https://o3.security/vulnerability/CVE-2023-37905","summary":"Cross-site Scripting (XSS) in Source Mode of Editor in ckeditor-wordcount-plugin","details":"ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the `ckeditor-wordcount-plugin` plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. This issue has been addressed in version 1.17.12 of the `ckeditor-wordcount-plugin` plugin and users are advised to upgrade. There are no known workarounds for this vulnerability.\n\n","published":"2023-07-21T19:35:49.656Z","modified":"2026-08-08T03:47:41.643354011Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"ckeditor-wordcount-plugin","fixedVersion":"1.17.12"}],"fix":{"url":"https://github.com/w8tcha/CKEditor-WordCount-Plugin/commit/0f03b3e5b7c1409998a13aba3a95396e6fa349d8","label":"w8tcha/CKEditor-WordCount-Plugin@0f03b3e"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37905.json"},{"type":"ADVISORY","url":"https://github.com/TYPO3/typo3/security/advisories/GHSA-m8fw-p3cr-6jqc"},{"type":"ADVISORY","url":"https://github.com/w8tcha/CKEditor-WordCount-Plugin/security/advisories/GHSA-q9w4-w667-qqj4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37905"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-core-sa-2023-004"},{"type":"FIX","url":"https://github.com/w8tcha/CKEditor-WordCount-Plugin/commit/0f03b3e5b7c1409998a13aba3a95396e6fa349d8"},{"type":"FIX","url":"https://github.com/w8tcha/CKEditor-WordCount-Plugin/commit/a4b154bdf35b3465320136fcb078f196b437c2f1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:41.643354011Z"}}