CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-118
Vulnerability Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before 1.5.1, from 1.6.0 before 1.6.4.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13980
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Wojciech Kukowski (salmonek)
- Wojciech Kukowski (salmonek)
- Greg Knaddison (greggles)
- Juraj Nemec (poker10)
- Jess (xjm)
References
More from Drupal
View All →Affected Vendor
Drupal
View all reports →