Skip to content

v44.2.1

Latest
Compare
Choose a tag to compare
@CKEditorBot CKEditorBot released this 20 Feb 09:29
· 120 commits to master since this release
4e45feb

We are happy to announce the release of CKEditor 5 v44.2.1.

During a recent internal audit, we identified a cross-site scripting (XSS) vulnerability in the CKEditor 5 real-time collaboration package (CVE-2025-25299). This vulnerability can lead to unauthorized JavaScript code execution and affects user markers, which represent users' positions within the document.

This vulnerability affects only installations with real-time collaborative editing enabled.

You can read more details in the relevant security advisory and contact us if you have more questions.

Bug fixes

  • comments: Fixed a few scenarios for which creating a new comment thread was impossible (for example, when a selection was made on multiple table cells). This was a regression introduced in v44.2.0.

Other changes

Released packages

Check out the Versioning policy guide for more information.

Released packages (summary)

Other releases: