Ckeditor 4.4.7 Shell Upload / Cross Site Scripting

Ckeditor version 4.4.7.x suffers from cross site scripting and remote shell upload vulnerabilities.