{"id":"GHSA-m8fw-p3cr-6jqc","aliases":[],"url":"https://o3.security/vulnerability/GHSA-m8fw-p3cr-6jqc","summary":"Cross-Site Scripting in CKEditor4 WordCount Plugin","details":"> ### CVSS: `CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C` (4.4) \n\n### Problem\nThe [WordCount](https://ckeditor.com/cke4/addon/wordcount) plugin ([`npm:ckeditor-wordcount-plugin`](https://www.npmjs.com/package/ckeditor-wordcount-plugin)) for CKEditor4 is vulnerable to cross-site scripting when switching to the source code mode. This plugin is enabled via the `Full.yaml` configuration present, but is not active in the default configuration.\n\nIn default scenarios, exploiting this vulnerability requires a valid backend user account. However, if custom plugins are used on the website frontend, which accept and reflect rich-text content submitted by users, no authentication is required.\n\n### Solution\nUpdate to TYPO3 versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30 that fix the problem described above.\n\n### Credits\nThanks to Sybille Peters who reported this issue, and to TYPO3 core & security team member Oliver Hader who fixed the issue.\n\n### References\n* [TYPO3-CORE-SA-2023-004](https://typo3.org/security/advisory/typo3-core-sa-2023-004)\n* https://github.com/w8tcha/CKEditor-WordCount-Plugin/security/advisories/GHSA-q9w4-w667-qqj4","published":"2023-07-25T19:11:43Z","modified":"2026-02-04T04:27:36.085478Z","cvss":{"score":4.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms-rte-ckeditor","fixedVersion":"9.5.42"},{"ecosystem":"Packagist","name":"typo3/cms-rte-ckeditor","fixedVersion":"10.4.39"},{"ecosystem":"Packagist","name":"typo3/cms-rte-ckeditor","fixedVersion":"11.5.30"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/TYPO3/typo3/security/advisories/GHSA-m8fw-p3cr-6jqc"},{"type":"PACKAGE","url":"https://github.com/TYPO3/typo3"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-core-sa-2023-004"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-04T04:27:36.085478Z"}}