Public Ticket #18109

Security issue: django-ckeditor bundles CKEditor 4.22.1

Open
Comments
DexignLab
Oleg Ivanchenko replied 1 hour ago on June 28, 2025 at 03:47 AM

Thank you Nilesh,

Looking for the new version :-) 

Kind regards,

Oleg

DexignLab
Nilesh Nama replied 12 hours ago on June 27, 2025 at 04:32 PM

Hello Sir,

Thank you your suggestion and its already in our queue and
Yes, we are migrating to CKEditor 5  and will fix the existed issues. we will release the updated version in next week.

Lets us know if you have any other query.

Thanks 

Nilesh Nama

DexignZone Team

DexignLab
Nilesh Nama replied 19 hours ago on June 27, 2025 at 09:52 AM

Hello Sir,

Thanks for being our customer.

We have received your Ticket , we will check and update you within 24 hours. 

Thanks

Nilesh Nama

DexignZone Team

DexignLab
Oleg Ivanchenko replied started the conversation 1 day ago on June 27, 2025 at 03:18 AM

Hello,

There is a security warning on use of CKEditor 4:

?: (ckeditor.W001) django-ckeditor bundles CKEditor 4.22.1 which isn't supported anymore and which does have unfixed security issues, see for example https://ckeditor.com/cke4/release/CKEditor-4.24.0-LTS . You should consider strongly switching to a different editor (maybe CKEditor 5 respectively django-ckeditor-5 after checking whether the CKEditor 5 license terms work for you) or switch to the non-free CKEditor 4 LTS package. See https://ckeditor.com/ckeditor-4-support/ for more on this. (Note! This notice has been added by the django-ckeditor developers and we are not affiliated with CKSource and were not involved in the licensing change, so please refrain from complaining to us. Thanks.)

Are there any plans of migrating to CKEditor 5 or any other fix of the issue?

Thank you in advance,

Oleg