Fixed an XSS vulnerability in the core module reported by GitHub Security Lab team member Kevin Backhouse.
Fixed a Regular expression Denial of Service (ReDoS) vulnerability in dialog plugin discovered by the CKEditor 4 team during our regular security audit.
Issue summary: The vulnerability allowed to abuse a dialog input validator regular expression, which could cause a significant performance drop resulting in a browser tab freeze. See CVE-2022-24729 for more details.
You can read more details in the relevant security advisory and contact us if you have more questions.
An upgrade is highly recommended!
Web Spell Checker ended support for WebSpellChecker Dialog on December 31st, 2021. This means the plugin is not supported any longer. Therefore, we decided to deprecate and remove the WebSpellChecker Dialog plugin from CKEditor 4 presets.
#5097: [Chrome] Fixed: Incorrect conversion of points to pixels while using
multipleattribute had incorrect styling. Thanks to John R. D'Orazio!
- #5093: Deprecated and removed WebSpellChecker Dialog from presets.
#5127: Deprecated the
CKEDITOR.rndproperty to discourage using it in a security-sensitive context.
- #5087: Improved the jQuery adapter by replacing a deprecated jQuery API with existing counterparts. Thanks to Fran Boon!
#5128: Improved the Emoji definitions encoding set by the