CVE-2025-13980: CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-118
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before 1.5.1, from 1.6.0 before 1.6.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13980?
CVE-2025-13980 is classified as a moderately critical access bypass vulnerability.
How do I fix CVE-2025-13980?
To mitigate CVE-2025-13980, upgrade CKEditor 5 Premium Features to version 1.2.10 or later.
What versions of CKEditor 5 Premium Features are affected by CVE-2025-13980?
CVE-2025-13980 affects CKEditor 5 Premium Features versions from 0.0.0 up to but not including 1.2.10, as well as several other versions up to 1.6.0.
What type of vulnerability is CVE-2025-13980?
CVE-2025-13980 is an authentication bypass vulnerability allowing functionality bypass in CKEditor 5 Premium Features.
Is there a recommended response for CVE-2025-13980?
The recommended response for CVE-2025-13980 is to immediately upgrade to a patched version of CKEditor 5 Premium Features.