DRUPAL-CORE-2021-005

    Dashboard / Vulnerabilities / DRUPAL-CORE-2021-005

    DRUPAL-CORE-2021-005

    Published: 12 Aug 2021Last Modified: 10 Dec 2025

    Summary:

    Details: The Drupal project uses the [CKEditor](https://github.com/ckeditor/ckeditor4), library for WYSIWYG editing. CKEditor has released [a security update that impacts Drupal](https://ckeditor.com/blog/ckeditor-4.16.2-with-browser-improvements-and-security-fixes/). Vulnerabilities are possible if Drupal is configured to allow use of the CKEditor library for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access. For more information, see [CKEditor's announcement of the release](https://ckeditor.com/blog/ckeditor-4.16.2-with-browser-improvements-and-security-fixes/). This advisory is not covered by [Drupal Steward](/steward).

    Affected packages

    Package

    Name: drupal/core

    Purl: pkg:composer/drupal/core

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 8.0.0
    Fixed -8.9.18

    Affected versions

    8.0.0
    8.0.1
    8.0.2
    8.0.3
    8.0.4
    8.0.5
    8.0.6

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DRUPAL-CORE-2021-005 | CVE-DB