- #4617: Fixed: Autocomplete is not accessible in inline editors.
- #4493: Fixed: The drop-down label does not reflect the current value of the drop-down.
- #1572: Fixed: A paragraph before or after a widget cannot be removed. Thanks to bunglegrind!
#4301: Fixed: Pasted content is overwritten when pasted in an initially empty editor with the
- #4351: Fixed: Incorrect values for RGBA/HSLA colors in Color Dialog.
- #4509: Fixed: Incorrect handling of drag & drop inside widgets and nested editables.
- #4611: [Android, iOS] Fixed: Incorrect hover styles for buttons in the toolbar on mobile devices.
#4652: Fixed: Event data set to
falseis treated as an event cancelation.
Fixed ReDoS vulnerability in the Autolink plugin.
Issue summary: It was possible to execute a ReDoS-type attack inside CKEditor 4 by persuading a victim to paste a specially crafted URL-like text into the editor and press Enter or Space.
Fixed ReDoS vulnerability in the Advanced Tab for Dialogs plugin.
Issue summary: It was possible to execute a ReDoS-type attack inside CKEditor 4 by persuading a victim to paste a specially crafted text into the Styles dialog.
An upgrade is highly recommended!
- #2800: Unsupported image formats are now gracefully handled by the Paste from Word plugin on paste, additionally showing descriptive error messages.
- #2800: Unsupported image formats are now gracefully handled by the Paste from LibreOffice plugin on paste, additionally showing descriptive error messages.
- #3582: Introduced smart positioning of the Autocomplete panel used by the Mentions and Emoji plugins. The panel will now be additionally positioned related to the browser viewport to be always fully visible.
#4388: Added the option to remove an iframe created with the IFrame Dialog plugin from the sequential keyboard navigation using the
tabindexattribute. Thanks to Timo Kirkkala!
- #1134: [Safari] Fixed: Paste from Word does not embed images.
- #2800: Fixed: No images are imported from Microsoft Word when the content is pasted via the Paste from Word plugin if there is at least one image of unsupported format.
- #4379: [Edge] Fixed: Incorrect detection of the high contrast mode.
- #4422: Fixed: Missing space between the button name and the keyboard shortcut inside the button label in the high contrast mode.
- #2208: [IE] Fixed: The Autolink plugin duplicates the native browser implementation.
- #1824: Fixed: The Autolink plugin should require the Link plugin.
#4253: Fixed: The Editor Placeholder plugin throws an error during the editor initialization with
config.fullPageenabled when there is no
<body>tag in the editor content.
#4372: Fixed: The Autogrow plugin changes the editor's width when used with an absolute
#4358: Introduced the
CKEDITOR.tools.colorclass which adds colors validation and methods for converting colors between various formats: named colors, HEX, RGB, RGBA, HSL and HSLA.
#3782: Moved the
CKEDITOR.plugins.pastetools.filters.word.imagesfilters to the
CKEDITOR.plugins.pastetools.filtersare now available under the
CKEDITOR.ajaxspecialized loading methods for loading binary (
CKEDITOR.ajax.loadBinary()) and text (
Issue summary: It was possible to execute an XSS-type attack inside CKEditor 4 by persuading a victim to paste a specially crafted HTML code into the Color Button dialog.
An upgrade is highly recommended!
#4293: Fixed: The
CKEDITOR.inlineAll()method tries to initialize inline editor also on elements with an editor already attached to them.
- #3961: Fixed: The Table Resize plugin prevents editing of merged cells.
- #3649: Fixed: Applying a block format should remove existing block styles.
- #4282: Fixed: The script loader does not execute callback for scripts already loaded when called for the second time. Thanks to Alexander Korotkevich!
#4273: Fixed: A memory leak in the
CKEDITOR.domReady()method connected with not removing
loadevent listeners. Thanks to rohit1!
#1330: Fixed: Incomplete CSS margin parsing if an
0value is used.
#4286: Fixed: The Auto Grow plugin causes the editor width to be set to
0on editor resize.
- #848: Fixed: Arabic text not being "bound" correctly when pasting. Thanks to Thomas Hunkapiller and J. Ivan Duarte Rodríguez!
#3940: Introduced the
colorNameproperty for customizing foreground and background styles in the Color Button plugin via the
- #3793: Introduced the Editor Placeholder plugin.
- #1795: The colors picked from the Color Dialog are now stored in the Color Button palette and can be reused easily.
- #3783: The colors used in the document are now displayed as a part of the Color Button palette.
- #4060: Fixed: The content inside a widget nested editable is escaped twice.
- #4183: [Safari] Fixed: Incorrect image dimensions when using the Easy Image plugin alongside the IFrame Editing Area plugin.
- #3693: Fixed: Incorrect default values for several Color Button configuration variables in the API documentation.
#3795: Fixed: Setting the
config.dataIndentationCharsconfiguration option to an empty string is ignored and replaced by a tab (
\t) character. Thanks to Thomas Grinderslev!
- #4107: Fixed: Multiple Autocomplete instances cause keyboard navigation issues.
#4041: Fixed: The
selection.scrollIntoViewmethod throws an error when the editor selection is not set.
- #3361: Fixed: Loading multiple custom editor configurations is prone to a race condition between these.
- #4007: Fixed: Screen readers do not announce the Rich Combo plugin is collapsed or expanded.
#4141: Fixed: The styles are incorrectly applied when there is a
<select>element inside the editor.
- #2607: Fixed: The Emoji plugin SVG icons file is not loaded in CORS context.
#3866: Fixed: The
config.readOnlyconfiguration option not considered for startup read-only mode of inline editor.
- #3931: [IE] Fixed: An error is thrown when pasting using the Paste button after accepting the browser Clipboard Access Prompt dialog.
- #3938: Fixed: Cannot navigate the Autocomplete panel with the keyboard after switching to source mode.
- #2823: [IE] Fixed: Cannot resize the last table column using the Table Resize plugin.
- #909: Fixed: The Table Resize plugin does not work when the editor is placed in an absolutely positioned container. Thanks to Roland Petto!
- #1959: Fixed: The Table Resize plugin does not work in a maximized editor when the Div Editing Area feature is enabled. Thanks to Roland Petto!
#3156: Fixed: Autolink
config.autolink_emailRegexoptions are not customizable. Thanks to Sergiy Dobrovolsky!
- #624: Fixed: Notification does not work with the bottom toolbar location.
- #3000: Fixed: Auto Embed does not work with the bottom toolbar location.
#1883: Fixed: The
editor.resize()method does not work with CSS units.
- #3926: Fixed: Dragging and dropping a widget sometimes produces an error.
- #4008: Fixed: Remove Format does not work with a collapsed selection.
- #3998: Fixed: An error is thrown when switching to the source mode using a custom Ctrl + Enter keystroke with the Widget plugin present.