CVE-2014-5191: The Preview plugin in CKEditor allows Cross-site scripting (XSS)
(updated )
Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References
Detect and mitigate CVE-2014-5191 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →