CVE-2025-61261

A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:angular:angular:18.0.0:-:*:*:*:node.js:*:*
cpe:2.3:a:ckeditor:ckeditor5:46.1.0:*:*:*:*:*:*:*

History

11 Dec 2025, 23:42

Type Values Removed Values Added
References () https://github.com/ckeditor/ckeditor5/releases/tag/v46.1.0 - () https://github.com/ckeditor/ckeditor5/releases/tag/v46.1.0 - Release Notes
References () https://senscybersecurity.nl/cve-2025-61261-explained/ - () https://senscybersecurity.nl/cve-2025-61261-explained/ - Exploit, Third Party Advisory
Summary
  • (es) Una vulnerabilidad reflejada de cross-site scripting (XSS) en CKeditor v46.1.0 y Angular v18.0.0 permite a los atacantes ejecutar código arbitrario en el contexto del navegador de un usuario mediante la inyección de una carga útil manipulada.
First Time Ckeditor ckeditor5
Ckeditor
Angular
Angular angular
CPE cpe:2.3:a:ckeditor:ckeditor5:46.1.0:*:*:*:*:*:*:*
cpe:2.3:a:angular:angular:18.0.0:-:*:*:*:node.js:*:*

07 Nov 2025, 20:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

07 Nov 2025, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-07 19:16

Updated : 2025-12-11 23:42


NVD link : CVE-2025-61261

Mitre link : CVE-2025-61261

CVE.ORG link : CVE-2025-61261


JSON object : View

Products Affected

angular

  • angular

ckeditor

  • ckeditor5
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')