CVE-2025-13980
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2026-01-28
Last updated on: 2026-02-12
Assigner: Drupal.org
Description
Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before 1.5.1, from 1.6.0 before 1.6.4.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| cksource | ckeditor_5_premium_features | to 1.2.10 (exc) |
| cksource | ckeditor_5_premium_features | From 1.3.0 (inc) to 1.3.6 (exc) |
| cksource | ckeditor_5_premium_features | From 1.4.0 (inc) to 1.4.3 (exc) |
| cksource | ckeditor_5_premium_features | From 1.6.0 (inc) to 1.6.4 (exc) |
| cksource | ckeditor_5_premium_features | 1.5.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |