Security Updates:
-
Fixed ReDoS vulnerability in the Autolink plugin.
Issue summary: It was possible to execute a ReDoS-type attack inside CKEditor 4 by persuading a victim to paste a specially crafted URL-like text into the editor and press Enter or Space.
-
Fixed ReDoS vulnerability in the Advanced Tab for Dialogs plugin.
Issue summary: It was possible to execute a ReDoS-type attack inside CKEditor 4 by persuading a victim to paste a specially crafted text into the Styles dialog.
An upgrade is highly recommended!
New Features:
- #2800: Unsupported image formats are now gracefully handled by the Paste from Word plugin on paste, additionally showing descriptive error messages.
- #2800: Unsupported image formats are now gracefully handled by the Paste from LibreOffice plugin on paste, additionally showing descriptive error messages.
- #3582: Introduced smart positioning of the Autocomplete panel used by the Mentions and Emoji plugins. The panel will now be additionally positioned related to the browser viewport to be always fully visible.
-
#4388: Added the option to remove an iframe created with the IFrame Dialog plugin from the sequential keyboard navigation using the
tabindex
attribute. Thanks to Timo Kirkkala!
Fixed Issues:
- #1134: [Safari] Fixed: Paste from Word does not embed images.
- #2800: Fixed: No images are imported from Microsoft Word when the content is pasted via the Paste from Word plugin if there is at least one image of unsupported format.
- #4379: [Edge] Fixed: Incorrect detection of the high contrast mode.
- #4422: Fixed: Missing space between the button name and the keyboard shortcut inside the button label in the high contrast mode.
- #2208: [IE] Fixed: The Autolink plugin duplicates the native browser implementation.
- #1824: Fixed: The Autolink plugin should require the Link plugin.
-
#4253: Fixed: The Editor Placeholder plugin throws an error during the editor initialization with
config.fullPage
enabled when there is no<body>
tag in the editor content. -
#4372: Fixed: The Autogrow plugin changes the editor's width when used with an absolute
config.width
value.
API Changes:
-
#4358: Introduced the
CKEDITOR.tools.color
class which adds colors validation and methods for converting colors between various formats: named colors, HEX, RGB, RGBA, HSL and HSLA. -
#3782: Moved the
CKEDITOR.plugins.pastetools.filters.word.images
filters to theCKEDITOR.plugins.pastetools.filters.image
namespace. -
#4297: All
CKEDITOR.plugins.pastetools.filters
are now available under theCKEDITOR.pasteTools
alias. -
#4394: Introduced
CKEDITOR.ajax
specialized loading methods for loading binary (CKEDITOR.ajax.loadBinary()
) and text (CKEDITOR.ajax.loadText()
) data.
Other Changes:
- The WebSpellChecker (WSC) plugin is now disabled by default in Standard and Full presets. It can be enabled via
extraPlugins
configuration option.
Security Updates:
-
Fixed XSS vulnerability in the Color History feature reported by Mark Wade.
Issue summary: It was possible to execute an XSS-type attack inside CKEditor 4 by persuading a victim to paste a specially crafted HTML code into the Color Button dialog.
An upgrade is highly recommended!
Fixed Issues:
-
#4293: Fixed: The
CKEDITOR.inlineAll()
method tries to initialize inline editor also on elements with an editor already attached to them. - #3961: Fixed: The Table Resize plugin prevents editing of merged cells.
- #3649: Fixed: Applying a block format should remove existing block styles.
- #4282: Fixed: The script loader does not execute callback for scripts already loaded when called for the second time. Thanks to Alexander Korotkevich!
-
#4273: Fixed: A memory leak in the
CKEDITOR.domReady()
method connected with not removingload
event listeners. Thanks to rohit1! -
#1330: Fixed: Incomplete CSS margin parsing if an
auto
or0
value is used. -
#4286: Fixed: The Auto Grow plugin causes the editor width to be set to
0
on editor resize. - #848: Fixed: Arabic text not being "bound" correctly when pasting. Thanks to Thomas Hunkapiller and J. Ivan Duarte Rodríguez!
API Changes:
-
#3649: Added a new
stylesRemove
editor event.
Other Changes:
-
#4262: Removed the global reference to the
stylesLoaded
variable. Thanks to Levi Carter! - Updated the Export to PDF plugin to
1.0.1
version:- Improved external CSS support for classic editor by handling exceptions and displaying convenient error messages.
New features:
-
#3940: Introduced the
colorName
property for customizing foreground and background styles in the Color Button plugin via theconfig.colorButton_foreStyle
andconfig.colorButton_backStyle
configuration options. - #3793: Introduced the Editor Placeholder plugin.
- #1795: The colors picked from the Color Dialog are now stored in the Color Button palette and can be reused easily.
- #3783: The colors used in the document are now displayed as a part of the Color Button palette.
Fixed Issues:
- #4060: Fixed: The content inside a widget nested editable is escaped twice.
- #4183: [Safari] Fixed: Incorrect image dimensions when using the Easy Image plugin alongside the IFrame Editing Area plugin.
- #3693: Fixed: Incorrect default values for several Color Button configuration variables in the API documentation.
-
#3795: Fixed: Setting the
config.dataIndentationChars
configuration option to an empty string is ignored and replaced by a tab (\t
) character. Thanks to Thomas Grinderslev! - #4107: Fixed: Multiple Autocomplete instances cause keyboard navigation issues.
-
#4041: Fixed: The
selection.scrollIntoView
method throws an error when the editor selection is not set. - #3361: Fixed: Loading multiple custom editor configurations is prone to a race condition between these.
- #4007: Fixed: Screen readers do not announce the Rich Combo plugin is collapsed or expanded.
-
#4141: Fixed: The styles are incorrectly applied when there is a
<select>
element inside the editor.
Fixed Issues:
- #2607: Fixed: The Emoji plugin SVG icons file is not loaded in CORS context.
-
#3866: Fixed: The
config.readOnly
configuration option not considered for startup read-only mode of inline editor. - #3931: [IE] Fixed: An error is thrown when pasting using the Paste button after accepting the browser Clipboard Access Prompt dialog.
- #3938: Fixed: Cannot navigate the Autocomplete panel with the keyboard after switching to source mode.
- #2823: [IE] Fixed: Cannot resize the last table column using the Table Resize plugin.
- #909: Fixed: The Table Resize plugin does not work when the editor is placed in an absolutely positioned container. Thanks to Roland Petto!
- #1959: Fixed: The Table Resize plugin does not work in a maximized editor when the Div Editing Area feature is enabled. Thanks to Roland Petto!
-
#3156: Fixed: Autolink
config.autolink_urlRegex
andconfig.autolink_emailRegex
options are not customizable. Thanks to Sergiy Dobrovolsky! - #624: Fixed: Notification does not work with the bottom toolbar location.
- #3000: Fixed: Auto Embed does not work with the bottom toolbar location.
-
#1883: Fixed: The
editor.resize()
method does not work with CSS units. - #3926: Fixed: Dragging and dropping a widget sometimes produces an error.
- #4008: Fixed: Remove Format does not work with a collapsed selection.
- #3998: Fixed: An error is thrown when switching to the source mode using a custom Ctrl + Enter keystroke with the Widget plugin present.
Other Changes:
- Updated WebSpellChecker (WSC) and SpellCheckAsYouType (SCAYT) plugins:
- Fixed: Active Autocomplete panel causes active suggestions to be unnecessarily checked by the SCAYT spell checking mechanism.
Security Updates:
-
Fixed XSS vulnerability in the HTML data processor reported by Michał Bentkowski of Securitum.
Issue summary: It was possible to execute XSS inside CKEditor after persuading the victim to: (i) switch CKEditor to source mode, then (ii) paste a specially crafted HTML code, prepared by the attacker, into the opened CKEditor source area, and (iii) switch back to WYSIWYG mode or (i) copy the specially crafted HTML code, prepared by the attacker and (ii) paste it into CKEditor in WYSIWYG mode.
-
Fixed XSS vulnerability in the WebSpellChecker plugin reported by Pham Van Khanh from Viettel Cyber Security.
Issue summary: It was possible to execute XSS using CKEditor after persuading the victim to: (i) switch CKEditor to source mode, then (ii) paste a specially crafted HTML code, prepared by the attacker, into the opened CKEditor source area, then (iii) switch back to WYSIWYG mode, and (iv) preview CKEditor content outside CKEditor editable area.
An upgrade is highly recommended!
New features:
- #2374: Added support for pasting rich content from LibreOffice Writer with the Paste from LibreOffice plugin.
- #2583: Changed emoji suggestion box to show the matched emoji name instead of an ID.
- #3748: Improved the color button state to reflect the selected editor content colors.
- #3661: Improved the Print plugin to respect styling rendered by the Preview plugin.
-
#3547: Active dialog tab now has the
aria-selected="true"
attribute. -
#3441: Improved
widget.getClipboardHtml()
support for dragging and dropping multiple widgets.
Fixed Issues:
- #3587: [Edge, IE] Fixed: Widget with form input elements loses focus during typing.
-
#3705: [Safari] Fixed: Safari incorrectly removes blocks with the
editor.extractSelectedHtml()
method after selecting all content. -
#1306: Fixed: The Font plugin creates nested HTML
<span>
tags when reapplying the same font multiple times. - #3498: Fixed: The editor throws an error during the copy operation when a widget is partially selected.
- #2517: [Chrome, Firefox, Safari] Fixed: Inserting a new image when the selection partially covers an existing enhanced image widget throws an error.
- #3007: [Chrome, Firefox, Safari] Fixed: Cannot modify the editor content once the selection is released over a widget.
- #3698: Fixed: Cutting the selected text when a widget is partially selected merges paragraphs.
API Changes:
- #3387: Added the CKEDITOR.ui.richCombo.select() method.
-
#3727: Added new
textColor
andbgColor
commands that apply the selected color chosen by the Color Button plugin. -
#3728: Added new
font
andfontSize
commands that apply the selected font style chosen by the Font plugin. -
#3842: Added the
editor.getSelectedRanges()
alias. - #3775: Widget mask and parts can now be refreshed dynamically via API calls.