Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 Youtube allows Cross-Site Scripting (XSS).This issue affects CKEditor5 Youtube: from 0.0.0 before 1.0.3.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
0.0.0 (semver) before 1.0.4
Credits
nico.b
Brahim Khouy (b.khouy)
Abderrahim GHAZALI ð¤ (g.abderrahim)
nico.b
Greg Knaddison (greggles)
References
www.drupal.org/sa-contrib-2025-081