« See all

CKEditor 4.18 browser bugfix and security patches

CKEditor on the first plan and some workers between the editor

We are happy to announce another major release of CKEditor 4. CKEditor 4.18 comes with important security fixes for the HTML processing core module and dialog plugin. It also includes important bug fix for Paste From Word plugin in the latest version of Chrome. We have also decided to make the WebSpellChecker Dialog plugin obsolete due to its end of life. Check out CKEditor 4.18 and find out, what was improved!

# Security fixes

We keep on striving to deliver the best, most secure editing solution for our users. Fast and reliable response to security threats effects in more frequent versions being released, one of which is the current 4.18

The latest version brings a patch for a potential security vulnerability in CKEditor 4 HTML processing core module reported by GitHub Security Lab team member Kevin Backhouse. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code (CVE-2022-24728).

A potential Regular expression Denial of Service vulnerability in the CKEditor 4 dialog plugin was discovered by the CKEditor 4 team during our standard security audit. The vulnerability allowed to abuse a dialog input validator regular expression, which could cause a significant performance drop (CVE-2022-24729). The current release patches this vulnerability.

It is always strongly advised to update your copy of CKEditor 4 promptly to avoid any potential risk.

# Important changes

# Browser bug fixed

Chrome 98 introduced a bug causing incorrect pixel units calculation in the Paste From Word plugin resulting in the invalid size of some features like table borders. We decided to patch this issue by updating the convertToPx method mitigating the issue.

# WebSpellChecker Dialog support ended

Web Spell Checker ended support of WebSpellChecker Dialog on December 31st, 2021. This means the plugin is not supported any longer. Therefore, we decided to deprecate and remove the WebSpellChecker Dialog plugin from CKEditor 4 presets.

We strongly encourage everyone to choose one of the other available spellchecking solutions - Spell Check As You Type (SCAYT) or WProofreader.

# Release notes

Check out the release notes and contact us for more information.

# Download

Download CKEditor now and upgrade your installation or use your favorite package manager to install it!

# License

CKEditor is available under Open Source and Commercial licenses. Full details can be found on our license page.

# Reporting issues and contributing

Please report any new issues in the CKEditor 4 development repository and follow the instructions in the issue template. You can also contribute code and provide editor patches through pull requests.

# Support

Community support is available through Stack Overflow. Visit the resources page for additional options.

Share this post

Linkedin Reddit
CKEditor 5 v33.0.0 with improved conversion system and DLL builds for collaboration features
Github Writer now available with Mermaid support
Twitter Facebook Facebook Instagram Medium Linkedin GitHub Arrow down Phone Menu Close icon Check