Description
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP-T-Wap Cross-Site Scripting (1.13.2)
Joomla Improper Input Validation Vulnerability (CVE-2021-23131)
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.14)
OpenSSL Cryptographic Issues Vulnerability (CVE-2011-5095)
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Cross-Site Scripting (6.4.2)