Looking for the vulnerability index of Invicti's legacy products?
CKEditor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-17960) - Vulnerability Database

CKEditor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-17960)

Description

CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.

References