Skip to main content

Vendor/product archive

cksource / ckfinder CVEs

Beta · best-effort

4 CVEs tagged to cksource / ckfinder0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2016-20023

Published Dec 5, 2025

In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-63830

Published Nov 14, 2025

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15891

Published Sep 26, 2019

An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15862

Published Sep 26, 2019

An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was confi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1