Ckeditor · Ckeditor-Wordcount-Plugin · CVE-2023-37905
**Name of the Vulnerable Software and Affected Versions**
ckeditor-wordcount-plugin versions prior to 1.17.12
**Description**
The ckeditor-wordcount-plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. In default scenarios, exploiting this vulnerability requires a valid backend user account. However, if custom plugins are used on the website frontend, which accept and reflect rich-text content submitted by users, no authentication is required.
**Recommendations**
Update to version 1.17.12 of the ckeditor-wordcount-plugin plugin.
As a temporary workaround, consider disabling the plugin until a patch is available.
Update to TYPO3 versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30 that fix the problem described above.