CVE-2021-26271EPSS p79.7%
CVE-2021-26271CVE-2021-26271
ckeditor / ckeditor
Description
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
| EPSS | 1.97% probability of exploitation · percentile 79.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-25 |