{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-28343",
        "tracking": {
            "current_release_date": "2026-03-26T02:12:07.504708Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-28343",
            "initial_release_date": "2026-03-04T19:39:52.826575Z",
            "revision_history": [
                {
                    "date": "2026-03-04T19:39:52.826575Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-04T19:40:01.473155Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-05T00:21:04.128518Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (2).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-05T00:21:13.843809Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T20:38:49.414088Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-05T20:38:52.098056Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T20:47:08.134732Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-05T20:47:12.639009Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T23:39:34.871479Z",
                    "number": "9",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-03-06T00:20:46.996594Z",
                    "number": "10",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-03-06T14:53:21.266718Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-06T14:53:23.481497Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-06T18:38:50.475957Z",
                    "number": "13",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-17T19:25:17.656770Z",
                    "number": "14",
                    "summary": "Products connected (1).| Product Identifiers created (1)."
                },
                {
                    "date": "2026-03-17T19:25:22.304366Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:37:47.076280Z",
                    "number": "16",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:37:49.969165Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T18:16:33.721557Z",
                    "number": "18",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Identifiers created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-20T18:16:37.459288Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T18:17:20.099821Z",
                    "number": "20",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (3).| CWES updated (1).| Unknown change."
                },
                {
                    "date": "2026-03-26T02:10:17.823268Z",
                    "number": "21",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (81).| Product Identifiers created (59).| References created (4)."
                },
                {
                    "date": "2026-03-26T02:10:32.170817Z",
                    "number": "22",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "22"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<47.6.0",
                                "product": {
                                    "name": "vers:unknown/>=0|<47.6.0",
                                    "product_id": "CSAFPID-5759801"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "@ckeditor/ckeditor5-html-support"
                    }
                ],
                "category": "vendor",
                "name": "ckeditor"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.22.1+dfsg1-2ubuntu1",
                                        "product": {
                                            "name": "vers:unknown/4.22.1+dfsg1-2ubuntu1",
                                            "product_id": "CSAFPID-5913879",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.22.1%2Bdfsg1-2ubuntu1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.22.1+dfsg1-2ubuntu1.1",
                                        "product": {
                                            "name": "vers:unknown/4.22.1+dfsg1-2ubuntu1.1",
                                            "product_id": "CSAFPID-5913880",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.22.1%2Bdfsg1-2ubuntu1.1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913881"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ckeditor"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0-1",
                                        "product": {
                                            "name": "vers:unknown/9.0-1",
                                            "product_id": "CSAFPID-5913882",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@9.0-1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913883"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ldap-account-manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.7+dfsg-4syncable1",
                                        "product": {
                                            "name": "vers:unknown/4.4.7+dfsg-4syncable1",
                                            "product_id": "CSAFPID-5913884",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.4.7%2Bdfsg-4syncable1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913885"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "request-tracker4"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:25.10"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.4+dfsg1-3",
                                        "product": {
                                            "name": "vers:unknown/4.4.4+dfsg1-3",
                                            "product_id": "CSAFPID-5913805",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.4.4%2Bdfsg1-3?arch=source&distro=esm-apps/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.5.6+dfsg-1",
                                        "product": {
                                            "name": "vers:unknown/4.5.6+dfsg-1",
                                            "product_id": "CSAFPID-5913806",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.5.6%2Bdfsg-1?arch=source&distro=esm-apps/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.5.7+dfsg-1",
                                        "product": {
                                            "name": "vers:unknown/4.5.7+dfsg-1",
                                            "product_id": "CSAFPID-5913807",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.5.7%2Bdfsg-1?arch=source&distro=esm-apps/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.5.7+dfsg-2",
                                        "product": {
                                            "name": "vers:unknown/4.5.7+dfsg-2",
                                            "product_id": "CSAFPID-5913808",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.5.7%2Bdfsg-2?arch=source&distro=esm-apps/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.5.7+dfsg-2ubuntu0.16.04.1~esm1",
                                        "product": {
                                            "name": "vers:unknown/4.5.7+dfsg-2ubuntu0.16.04.1~esm1",
                                            "product_id": "CSAFPID-5913809",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.5.7%2Bdfsg-2ubuntu0.16.04.1~esm1?arch=source&distro=esm-apps/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.5.7+dfsg-2ubuntu0.16.04.1~esm2",
                                        "product": {
                                            "name": "vers:unknown/4.5.7+dfsg-2ubuntu0.16.04.1~esm2",
                                            "product_id": "CSAFPID-5913810",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.5.7%2Bdfsg-2ubuntu0.16.04.1~esm2?arch=source&distro=esm-apps/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.5.7+dfsg-2ubuntu0.16.04.1~esm3",
                                        "product": {
                                            "name": "vers:unknown/4.5.7+dfsg-2ubuntu0.16.04.1~esm3",
                                            "product_id": "CSAFPID-5913811",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.5.7%2Bdfsg-2ubuntu0.16.04.1~esm3?arch=source&distro=esm-apps/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913812"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ckeditor"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:16.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.5.7+dfsg-2",
                                        "product": {
                                            "name": "vers:unknown/4.5.7+dfsg-2",
                                            "product_id": "CSAFPID-5913823",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.5.7%2Bdfsg-2?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.5.7+dfsg-2ubuntu0.18.04.1",
                                        "product": {
                                            "name": "vers:unknown/4.5.7+dfsg-2ubuntu0.18.04.1",
                                            "product_id": "CSAFPID-5913824",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.5.7%2Bdfsg-2ubuntu0.18.04.1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.5.7+dfsg-2ubuntu0.18.04.1+esm1",
                                        "product": {
                                            "name": "vers:unknown/4.5.7+dfsg-2ubuntu0.18.04.1+esm1",
                                            "product_id": "CSAFPID-5913825",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.5.7%2Bdfsg-2ubuntu0.18.04.1%2Besm1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.5.7+dfsg-2ubuntu0.18.04.1+esm2",
                                        "product": {
                                            "name": "vers:unknown/4.5.7+dfsg-2ubuntu0.18.04.1+esm2",
                                            "product_id": "CSAFPID-5913826",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.5.7%2Bdfsg-2ubuntu0.18.04.1%2Besm2?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913827"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ckeditor"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.1-5",
                                        "product": {
                                            "name": "vers:unknown/4.4.1-5",
                                            "product_id": "CSAFPID-5913834",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.4.1-5?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.2-1",
                                        "product": {
                                            "name": "vers:unknown/4.4.2-1",
                                            "product_id": "CSAFPID-5913835",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.4.2-1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.2-2",
                                        "product": {
                                            "name": "vers:unknown/4.4.2-2",
                                            "product_id": "CSAFPID-5913836",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.4.2-2?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.2-2ubuntu0.1~esm1",
                                        "product": {
                                            "name": "vers:unknown/4.4.2-2ubuntu0.1~esm1",
                                            "product_id": "CSAFPID-5913837",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.4.2-2ubuntu0.1~esm1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913838"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "request-tracker4"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:18.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.11.1+dfsg-1",
                                        "product": {
                                            "name": "vers:unknown/4.11.1+dfsg-1",
                                            "product_id": "CSAFPID-5913839",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.11.1%2Bdfsg-1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.12.1+dfsg-1",
                                        "product": {
                                            "name": "vers:unknown/4.12.1+dfsg-1",
                                            "product_id": "CSAFPID-5913840",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.12.1%2Bdfsg-1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.12.1+dfsg-1ubuntu0.1",
                                        "product": {
                                            "name": "vers:unknown/4.12.1+dfsg-1ubuntu0.1",
                                            "product_id": "CSAFPID-5913841",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.12.1%2Bdfsg-1ubuntu0.1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.12.1+dfsg-1ubuntu0.1+esm1",
                                        "product": {
                                            "name": "vers:unknown/4.12.1+dfsg-1ubuntu0.1+esm1",
                                            "product_id": "CSAFPID-5913842",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.12.1%2Bdfsg-1ubuntu0.1%2Besm1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.12.1+dfsg-1ubuntu0.1+esm2",
                                        "product": {
                                            "name": "vers:unknown/4.12.1+dfsg-1ubuntu0.1+esm2",
                                            "product_id": "CSAFPID-5913843",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.12.1%2Bdfsg-1ubuntu0.1%2Besm2?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913844"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ckeditor"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:20.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.16.0+dfsg-2",
                                        "product": {
                                            "name": "vers:unknown/4.16.0+dfsg-2",
                                            "product_id": "CSAFPID-5913861",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.16.0%2Bdfsg-2?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.16.2+dfsg-1",
                                        "product": {
                                            "name": "vers:unknown/4.16.2+dfsg-1",
                                            "product_id": "CSAFPID-5913862",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.16.2%2Bdfsg-1?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.16.2+dfsg-1ubuntu0.1~esm1",
                                        "product": {
                                            "name": "vers:unknown/4.16.2+dfsg-1ubuntu0.1~esm1",
                                            "product_id": "CSAFPID-5913863",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.16.2%2Bdfsg-1ubuntu0.1~esm1?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.16.2+dfsg-1ubuntu0.1~esm2",
                                        "product": {
                                            "name": "vers:unknown/4.16.2+dfsg-1ubuntu0.1~esm2",
                                            "product_id": "CSAFPID-5913864",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.16.2%2Bdfsg-1ubuntu0.1~esm2?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913865"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ckeditor"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:22.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.22.1+dfsg1-2",
                                        "product": {
                                            "name": "vers:unknown/4.22.1+dfsg1-2",
                                            "product_id": "CSAFPID-5913875",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.22.1%2Bdfsg1-2?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.22.1+dfsg1-2ubuntu0.24.04.1~esm1",
                                        "product": {
                                            "name": "vers:unknown/4.22.1+dfsg1-2ubuntu0.24.04.1~esm1",
                                            "product_id": "CSAFPID-5913876",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.22.1%2Bdfsg1-2ubuntu0.24.04.1~esm1?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.22.1+dfsg1-2ubuntu0.24.04.1~esm2",
                                        "product": {
                                            "name": "vers:unknown/4.22.1+dfsg1-2ubuntu0.24.04.1~esm2",
                                            "product_id": "CSAFPID-5913877",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor@4.22.1%2Bdfsg1-2ubuntu0.24.04.1~esm2?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913878"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ckeditor"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:24.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/3.6.6.1+dfsg-1",
                                        "product": {
                                            "name": "vers:unknown/3.6.6.1+dfsg-1",
                                            "product_id": "CSAFPID-5913828",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor3@3.6.6.1%2Bdfsg-1?arch=source&distro=bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913829"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ckeditor3"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/5.7-1",
                                        "product": {
                                            "name": "vers:unknown/5.7-1",
                                            "product_id": "CSAFPID-5913830",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@5.7-1?arch=source&distro=bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/6.1-1",
                                        "product": {
                                            "name": "vers:unknown/6.1-1",
                                            "product_id": "CSAFPID-5913831",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@6.1-1?arch=source&distro=bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/6.2-1",
                                        "product": {
                                            "name": "vers:unknown/6.2-1",
                                            "product_id": "CSAFPID-5913832",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@6.2-1?arch=source&distro=bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913833"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ldap-account-manager"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:18.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/3.6.6.1+dfsg-3",
                                        "product": {
                                            "name": "vers:unknown/3.6.6.1+dfsg-3",
                                            "product_id": "CSAFPID-5913845",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor3@3.6.6.1%2Bdfsg-3?arch=source&distro=focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/3.6.6.1+dfsg-4",
                                        "product": {
                                            "name": "vers:unknown/3.6.6.1+dfsg-4",
                                            "product_id": "CSAFPID-5913846",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor3@3.6.6.1%2Bdfsg-4?arch=source&distro=focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913847"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ckeditor3"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/6.7-1",
                                        "product": {
                                            "name": "vers:unknown/6.7-1",
                                            "product_id": "CSAFPID-5913848",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@6.7-1?arch=source&distro=focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913849"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ldap-account-manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.3-2",
                                        "product": {
                                            "name": "vers:unknown/4.4.3-2",
                                            "product_id": "CSAFPID-5913850",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.4.3-2?arch=source&distro=focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.3-2+deb10u3build0.20.04.1",
                                        "product": {
                                            "name": "vers:unknown/4.4.3-2+deb10u3build0.20.04.1",
                                            "product_id": "CSAFPID-5913851",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.4.3-2%2Bdeb10u3build0.20.04.1?arch=source&distro=focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913852"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "request-tracker4"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:20.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/3.6.6.1+dfsg-7",
                                        "product": {
                                            "name": "vers:unknown/3.6.6.1+dfsg-7",
                                            "product_id": "CSAFPID-5913853",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor3@3.6.6.1%2Bdfsg-7?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913854"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ckeditor3"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.5-1",
                                        "product": {
                                            "name": "vers:unknown/7.5-1",
                                            "product_id": "CSAFPID-5913855",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@7.5-1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.7-1",
                                        "product": {
                                            "name": "vers:unknown/7.7-1",
                                            "product_id": "CSAFPID-5913856",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@7.7-1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913857"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ldap-account-manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.4+dfsg-2ubuntu1",
                                        "product": {
                                            "name": "vers:unknown/4.4.4+dfsg-2ubuntu1",
                                            "product_id": "CSAFPID-5913858",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.4.4%2Bdfsg-2ubuntu1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.4+dfsg-2ubuntu1.22.04.1",
                                        "product": {
                                            "name": "vers:unknown/4.4.4+dfsg-2ubuntu1.22.04.1",
                                            "product_id": "CSAFPID-5913859",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.4.4%2Bdfsg-2ubuntu1.22.04.1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913860"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "request-tracker4"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:22.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/3.6.6.1+dfsg-7",
                                        "product": {
                                            "name": "vers:unknown/3.6.6.1+dfsg-7",
                                            "product_id": "CSAFPID-5913866",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ckeditor3@3.6.6.1%2Bdfsg-7?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913867"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ckeditor3"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.3-1",
                                        "product": {
                                            "name": "vers:unknown/8.3-1",
                                            "product_id": "CSAFPID-5913868",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@8.3-1?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5-1",
                                        "product": {
                                            "name": "vers:unknown/8.5-1",
                                            "product_id": "CSAFPID-5913869",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@8.5-1?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913870"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ldap-account-manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.4+dfsg-2ubuntu1",
                                        "product": {
                                            "name": "vers:unknown/4.4.4+dfsg-2ubuntu1",
                                            "product_id": "CSAFPID-5913871",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.4.4%2Bdfsg-2ubuntu1?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.4+dfsg-2ubuntu2",
                                        "product": {
                                            "name": "vers:unknown/4.4.4+dfsg-2ubuntu2",
                                            "product_id": "CSAFPID-5913872",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.4.4%2Bdfsg-2ubuntu2?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.4.7+dfsg-1",
                                        "product": {
                                            "name": "vers:unknown/4.4.7+dfsg-1",
                                            "product_id": "CSAFPID-5913873",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.4.7%2Bdfsg-1?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913874"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "request-tracker4"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:24.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.9-1",
                                        "product": {
                                            "name": "vers:unknown/4.9-1",
                                            "product_id": "CSAFPID-5913813",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@4.9-1?arch=source&distro=xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/5.1-1",
                                        "product": {
                                            "name": "vers:unknown/5.1-1",
                                            "product_id": "CSAFPID-5913814",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@5.1-1?arch=source&distro=xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/5.2-1",
                                        "product": {
                                            "name": "vers:unknown/5.2-1",
                                            "product_id": "CSAFPID-5913815",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@5.2-1?arch=source&distro=xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/5.2-1ubuntu1",
                                        "product": {
                                            "name": "vers:unknown/5.2-1ubuntu1",
                                            "product_id": "CSAFPID-5913816",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/ldap-account-manager@5.2-1ubuntu1?arch=source&distro=xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913817"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ldap-account-manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.2.11-2",
                                        "product": {
                                            "name": "vers:unknown/4.2.11-2",
                                            "product_id": "CSAFPID-5913818",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.2.11-2?arch=source&distro=xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.2.12-3",
                                        "product": {
                                            "name": "vers:unknown/4.2.12-3",
                                            "product_id": "CSAFPID-5913819",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.2.12-3?arch=source&distro=xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.2.12-4",
                                        "product": {
                                            "name": "vers:unknown/4.2.12-4",
                                            "product_id": "CSAFPID-5913820",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.2.12-4?arch=source&distro=xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/4.2.12-5",
                                        "product": {
                                            "name": "vers:unknown/4.2.12-5",
                                            "product_id": "CSAFPID-5913821",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/request-tracker4@4.2.12-5?arch=source&distro=xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5913822"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "request-tracker4"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:16.04:LTS"
                    }
                ],
                "category": "vendor",
                "name": "Ubuntu"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<47.6.0",
                                "product": {
                                    "name": "vers:unknown/<47.6.0",
                                    "product_id": "CSAFPID-5763844",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:ckeditor:ckeditor5:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<47.6.0",
                                "product": {
                                    "name": "vers:unknown/>=0|<47.6.0",
                                    "product_id": "CSAFPID-5759802"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=29.0.0|<47.6.0",
                                "product": {
                                    "name": "vers:unknown/>=29.0.0|<47.6.0",
                                    "product_id": "CSAFPID-5873924"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "ckeditor5"
                    }
                ],
                "category": "vendor",
                "name": "CKEditor"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-28343",
            "cwe": {
                "id": "CWE-79",
                "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "### Impact\nA Cross-Site Scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration.\n\nThis vulnerability affects only installations where the editor configuration meets the following criteria:\n\n* [General HTML Support](https://ckeditor.com/docs/ckeditor5/latest/features/html/general-html-support.html) is enabled,\n* General HTML Support configuration allows inserting unsafe markup (see [Security](https://ckeditor.com/docs/ckeditor5/latest/features/html/general-html-support.html#security) section to learn more).\n\n### Patches\nThe problem has been recognized and patched. The fix will be available in version 47.6.0 (and above).\n\n### Workarounds\nCKEditor 5 recommends configuring General HTML Support securely to ensure that unsafe content is not accepted. Please refer to the [Security](https://ckeditor.com/docs/ckeditor5/latest/features/html/general-html-support.html#security) section for detailed guidance.\n\n### Credits\nCKEditor 5 would like to thank: \n- Emilio Kevin\n- Jeongwoo Lee, Younsoung Kim, Minseok Kim and Jinyeong Kim from ENKI Whitehat\n\nfor responsibly reporting this vulnerability.\n\n### For more information\nEmail us at [security@cksource.com](mailto:security@cksource.com) if you have any questions or comments about this advisory.",
                    "title": "github - https://github.com/advisories/GHSA-jrqm-vmqc-gm93"
                },
                {
                    "category": "description",
                    "text": "### Impact\nA Cross-Site Scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration.\n\nThis vulnerability affects only installations where the editor configuration meets the following criteria:\n\n* [General HTML Support](https://ckeditor.com/docs/ckeditor5/latest/features/html/general-html-support.html) is enabled,\n* General HTML Support configuration allows inserting unsafe markup (see [Security](https://ckeditor.com/docs/ckeditor5/latest/features/html/general-html-support.html#security) section to learn more).\n\n### Patches\nThe problem has been recognized and patched. The fix will be available in version 47.6.0 (and above).\n\n### Workarounds\nCKEditor 5 recommends configuring General HTML Support securely to ensure that unsafe content is not accepted. Please refer to the [Security](https://ckeditor.com/docs/ckeditor5/latest/features/html/general-html-support.html#security) section for detailed guidance.\n\n### Credits\nCKEditor 5 would like to thank: \n- Emilio Kevin\n- Jeongwoo Lee, Younsoung Kim, Minseok Kim and Jinyeong Kim from ENKI Whitehat\n\nfor responsibly reporting this vulnerability.\n\n### For more information\nEmail us at [security@cksource.com](mailto:security@cksource.com) if you have any questions or comments about this advisory.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-jrqm-vmqc-gm93.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-28343"
                },
                {
                    "category": "description",
                    "text": "CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-28343"
                },
                {
                    "category": "description",
                    "text": "CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-28343"
                },
                {
                    "category": "description",
                    "text": "CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/28xxx/CVE-2026-28343.json"
                },
                {
                    "category": "description",
                    "text": "CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Ubuntu%2FUBUNTU-CVE-2026-28343.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.0004",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "4.1",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent CVSS (V3) score, Is related to CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5759801",
                    "CSAFPID-5759802",
                    "CSAFPID-5763844",
                    "CSAFPID-5873924",
                    "CSAFPID-5913805",
                    "CSAFPID-5913806",
                    "CSAFPID-5913807",
                    "CSAFPID-5913808",
                    "CSAFPID-5913809",
                    "CSAFPID-5913810",
                    "CSAFPID-5913811",
                    "CSAFPID-5913812",
                    "CSAFPID-5913813",
                    "CSAFPID-5913814",
                    "CSAFPID-5913815",
                    "CSAFPID-5913816",
                    "CSAFPID-5913817",
                    "CSAFPID-5913818",
                    "CSAFPID-5913819",
                    "CSAFPID-5913820",
                    "CSAFPID-5913821",
                    "CSAFPID-5913822",
                    "CSAFPID-5913823",
                    "CSAFPID-5913824",
                    "CSAFPID-5913825",
                    "CSAFPID-5913826",
                    "CSAFPID-5913827",
                    "CSAFPID-5913828",
                    "CSAFPID-5913829",
                    "CSAFPID-5913830",
                    "CSAFPID-5913831",
                    "CSAFPID-5913832",
                    "CSAFPID-5913833",
                    "CSAFPID-5913834",
                    "CSAFPID-5913835",
                    "CSAFPID-5913836",
                    "CSAFPID-5913837",
                    "CSAFPID-5913838",
                    "CSAFPID-5913839",
                    "CSAFPID-5913840",
                    "CSAFPID-5913841",
                    "CSAFPID-5913842",
                    "CSAFPID-5913843",
                    "CSAFPID-5913844",
                    "CSAFPID-5913845",
                    "CSAFPID-5913846",
                    "CSAFPID-5913847",
                    "CSAFPID-5913848",
                    "CSAFPID-5913849",
                    "CSAFPID-5913850",
                    "CSAFPID-5913851",
                    "CSAFPID-5913852",
                    "CSAFPID-5913853",
                    "CSAFPID-5913854",
                    "CSAFPID-5913855",
                    "CSAFPID-5913856",
                    "CSAFPID-5913857",
                    "CSAFPID-5913858",
                    "CSAFPID-5913859",
                    "CSAFPID-5913860",
                    "CSAFPID-5913861",
                    "CSAFPID-5913862",
                    "CSAFPID-5913863",
                    "CSAFPID-5913864",
                    "CSAFPID-5913865",
                    "CSAFPID-5913866",
                    "CSAFPID-5913867",
                    "CSAFPID-5913868",
                    "CSAFPID-5913869",
                    "CSAFPID-5913870",
                    "CSAFPID-5913871",
                    "CSAFPID-5913872",
                    "CSAFPID-5913873",
                    "CSAFPID-5913874",
                    "CSAFPID-5913875",
                    "CSAFPID-5913876",
                    "CSAFPID-5913877",
                    "CSAFPID-5913878",
                    "CSAFPID-5913879",
                    "CSAFPID-5913880",
                    "CSAFPID-5913881",
                    "CSAFPID-5913882",
                    "CSAFPID-5913883",
                    "CSAFPID-5913884",
                    "CSAFPID-5913885"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-jrqm-vmqc-gm93"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-jrqm-vmqc-gm93"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-jrqm-vmqc-gm93.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-28343"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/28xxx/CVE-2026-28343.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28343"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-28343"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-28343"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-28343"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/28xxx/CVE-2026-28343.json"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Ubuntu%2FUBUNTU-CVE-2026-28343.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/ckeditor/ckeditor5/security/advisories/GHSA-jrqm-vmqc-gm93"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/ckeditor/ckeditor5/releases/tag/v47.6.0"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-jrqm-vmqc-gm93"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28343"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://github.com/ckeditor/ckeditor5/releases/tag/v29.0.0"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://ubuntu.com/security/CVE-2026-28343"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-28343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
                        "baseScore": 6.4,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-5759801",
                        "CSAFPID-5759802",
                        "CSAFPID-5763844",
                        "CSAFPID-5873924",
                        "CSAFPID-5913805",
                        "CSAFPID-5913806",
                        "CSAFPID-5913807",
                        "CSAFPID-5913808",
                        "CSAFPID-5913809",
                        "CSAFPID-5913810",
                        "CSAFPID-5913811",
                        "CSAFPID-5913812",
                        "CSAFPID-5913813",
                        "CSAFPID-5913814",
                        "CSAFPID-5913815",
                        "CSAFPID-5913816",
                        "CSAFPID-5913817",
                        "CSAFPID-5913818",
                        "CSAFPID-5913819",
                        "CSAFPID-5913820",
                        "CSAFPID-5913821",
                        "CSAFPID-5913822",
                        "CSAFPID-5913823",
                        "CSAFPID-5913824",
                        "CSAFPID-5913825",
                        "CSAFPID-5913826",
                        "CSAFPID-5913827",
                        "CSAFPID-5913828",
                        "CSAFPID-5913829",
                        "CSAFPID-5913830",
                        "CSAFPID-5913831",
                        "CSAFPID-5913832",
                        "CSAFPID-5913833",
                        "CSAFPID-5913834",
                        "CSAFPID-5913835",
                        "CSAFPID-5913836",
                        "CSAFPID-5913837",
                        "CSAFPID-5913838",
                        "CSAFPID-5913839",
                        "CSAFPID-5913840",
                        "CSAFPID-5913841",
                        "CSAFPID-5913842",
                        "CSAFPID-5913843",
                        "CSAFPID-5913844",
                        "CSAFPID-5913845",
                        "CSAFPID-5913846",
                        "CSAFPID-5913847",
                        "CSAFPID-5913848",
                        "CSAFPID-5913849",
                        "CSAFPID-5913850",
                        "CSAFPID-5913851",
                        "CSAFPID-5913852",
                        "CSAFPID-5913853",
                        "CSAFPID-5913854",
                        "CSAFPID-5913855",
                        "CSAFPID-5913856",
                        "CSAFPID-5913857",
                        "CSAFPID-5913858",
                        "CSAFPID-5913859",
                        "CSAFPID-5913860",
                        "CSAFPID-5913861",
                        "CSAFPID-5913862",
                        "CSAFPID-5913863",
                        "CSAFPID-5913864",
                        "CSAFPID-5913865",
                        "CSAFPID-5913866",
                        "CSAFPID-5913867",
                        "CSAFPID-5913868",
                        "CSAFPID-5913869",
                        "CSAFPID-5913870",
                        "CSAFPID-5913871",
                        "CSAFPID-5913872",
                        "CSAFPID-5913873",
                        "CSAFPID-5913874",
                        "CSAFPID-5913875",
                        "CSAFPID-5913876",
                        "CSAFPID-5913877",
                        "CSAFPID-5913878",
                        "CSAFPID-5913879",
                        "CSAFPID-5913880",
                        "CSAFPID-5913881",
                        "CSAFPID-5913882",
                        "CSAFPID-5913883",
                        "CSAFPID-5913884",
                        "CSAFPID-5913885"
                    ]
                }
            ],
            "title": "CVE-2026-28343"
        }
    ]
}