Skip to main content

Vendor archive

cksource CVEs

Beta · best-effort

8 CVEs tagged to vendor cksource0 Critical, 1 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2025-13980

Published Jan 28, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Feat…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-20023

Published Dec 5, 2025

In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-63830

Published Nov 14, 2025

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13245

Published Jan 9, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS)…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4771

Published Nov 16, 2023

A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckedi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15891

Published Sep 26, 2019

An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15862

Published Sep 26, 2019

An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was confi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-9349

Published Aug 27, 2019

The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1