CVE-2025-6674: CKEditor5 Youtube - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-081
Published Jun 26, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 Youtube allows Cross-Site Scripting (XSS).This issue affects CKEditor5 Youtube: from 0.0.0 before 1.0.3.
Affected Software
2 affected components
Drupal CKEditor5 Youtube>0.0.0, <1.0.3
Gabderrahim Ckeditor5 Youtube Drupal<1.0.4
Event History
Jun 26, 2025
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 9, 57515
Event
via FIRST·12:28 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-6674?
CVE-2025-6674 has been classified as a high severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2025-6674?
To fix CVE-2025-6674, upgrade the CKEditor5 Youtube module to version 1.0.3 or later.
3
What software is affected by CVE-2025-6674?
CVE-2025-6674 affects the Drupal CKEditor5 Youtube module versions prior to 1.0.3.
4
What type of vulnerability is CVE-2025-6674?
CVE-2025-6674 is categorized as a Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2025-6674 allow attackers to execute scripts?
Yes, CVE-2025-6674 can allow attackers to execute malicious scripts in the context of other users when exploited.