Huge News!Announcing our $40M Series B led by Abstract Ventures.Learn More
Socket
Sign inDemoInstall
Socket

ckeditor-dev

Package Overview
Dependencies
Maintainers
1
Versions
27
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

ckeditor-dev - npm Package Versions

12

4.5.11

Diff

Changelog

Source

CKEditor 4.5.11

Security Updates:

  • [Severity: minor] Fixed the target="_blank" vulnerability reported by James Gaskell.

    Issue summary: If a victim had access to a spoofed version of ckeditor.com via HTTP (e.g. due to DNS spoofing, using a hacked public network or mailicious hotspot), then when using a link to the ckeditor.com website it was possible for the attacker to change the current URL of the opening page, even if the opening page was protected with SSL.

    An upgrade is recommended.

New Features:

  • #14747: The Enhanced Image caption now supports the link target attribute.
  • #7154: Added support for the "Display Text" field to the Link dialog. Thanks to Ryan Guill!

Fixed Issues:

  • #13362: [Blink, WebKit] Fixed: Active widget element is not cached when it is losing focus and it is inside an editable element.
  • #13755: [Edge] Fixed: Pasting images does not work.
  • #13548: [IE] Fixed: Clicking the elements path disables Cut and Copy icons.
  • #13812: Fixed: When aborting file upload the placeholder for image is left.
  • #14659: [Blink] Fixed: Content scrolled to the top after closing the dialog in a <div>-based editor.
  • #14825: [Edge] Fixed: Focusing the editor causes unwanted scrolling due to dropped support for the setActive() method.
cksource
published 4.5.10 •

Changelog

Source

CKEditor 4.5.10

Fixed Issues:

  • #10750: Fixed: The editor does not escape the font-style family property correctly, removing quotes and whitespace from font names.
  • #14413: Fixed: The Auto Grow plugin with the config.autoGrow_onStartup option set to true does not work properly for an editor that is not visible.
  • #14451: Fixed: Numeric element ID not escaped properly. Thanks to Jakub Chalupa!
  • #14590: Fixed: Additional line break appearing after inline elements when switching modes. Thanks to dpidcock!
  • #14539: Fixed: JAWS reads "selected Blank" instead of "selected <widget name>" when selecting a widget.
  • #14701: Fixed: More precise labels for Enhanced Image and Placeholder widgets.
  • #14667: [IE] Fixed: Removing background color from selected text removes background color from the whole paragraph.
  • #14252: [IE] Fixed: Styles drop-down list does not always reflect the current style of the text line.
  • #14275: [IE9+] Fixed: onerror and onload events are not used in browsers it could have been used when loading scripts dynamically.
cksource
published 4.5.9 •

Changelog

Source

CKEditor 4.5.9

Fixed Issues:

cksource
published 4.5.8 •

Changelog

Source

CKEditor 4.5.8

New Features:

Fixed Issues:

cksource
published 4.5.7 •

Changelog

Source

CKEditor 4.5.7

New Features:

Fixed Issues:

cksource
published 4.5.6 •

Changelog

Source

CKEditor 4.5.6

New Features:

Other Changes:

  • Updated SCAYT (Spell Check As You Type):
    • New features:
    • Fixed issues:
      • #98: SCAYT affects dialog double-click. Fixed in SCAYT core.
      • #102: SCAYT core performance enhancements.
      • #104: SCAYT's spans leak into the clipboard and after pasting.
      • #105: A JavaScript error fired in case of multiple instances of CKEditor on one page.
      • #107: SCAYT should not check non-editable parts of content.
      • #108: Latest SCAYT copies the ID of the editor element to the iframe.
      • SCAYT stops working when CKEditor Undo plugin not enabled.
      • Issue with pasting SCAYT markup in CKEditor.
      • SCAYT stops working after pressing the Cancel button in the WSC dialog.
andineck
published 4.4.8 •

Changelog

Source

CKEditor 4.4.8

Security Updates:

  • Fixed XSS vulnerability in the HTML parser reported by Dheeraj Joshi and Prem Kumar.

    Issue summary: It was possible to execute XSS inside CKEditor after persuading the victim to: (i) switch CKEditor to source mode, then (ii) paste a specially crafted HTML code, prepared by the attacker, into the opened CKEditor source area, and (iii) switch back to WYSIWYG mode.

An upgrade is highly recommended!

Fixed Issues:

Other Changes:

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc