CVE Vulnerabilities

CVE-2025-13980

Authentication Bypass Using an Alternate Path or Channel

Published: Jan 28, 2026 | Modified: Feb 12, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before 1.5.1, from 1.6.0 before 1.6.4.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
Ckeditor_5_premium_featuresCksource*1.2.10 (excluding)
Ckeditor_5_premium_featuresCksource1.3.0 (including)1.3.6 (excluding)
Ckeditor_5_premium_featuresCksource1.4.0 (including)1.4.3 (excluding)
Ckeditor_5_premium_featuresCksource1.6.0 (including)1.6.4 (excluding)
Ckeditor_5_premium_featuresCksource1.5.0 (including)1.5.0 (including)

Potential Mitigations

References