CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2025-13980 MEDIUM

CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-118

CVSS 5.3 EPSS 0.27% Jan 28, 2026
CVE-2016-20023 MEDIUM

In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

CVSS 6.5 EPSS 0.34% Dec 5, 2025
CVE-2025-63830 MEDIUM

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

CVSS 6.1 EPSS 0.25% Nov 14, 2025
CVE-2024-13245 MEDIUM

CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009

CVSS 5.4 EPSS 0.22% Jan 9, 2025
CVE-2023-4771 MEDIUM

Cross-Site Scripting vulnerability in CKSource CKEditor

CVSS 6.1 EPSS 0.88% Nov 16, 2023
npm
CVE-2011-4972 HIGH

hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private…

CVSS 7.5 EPSS 1.74% Nov 13, 2019
CVE-2019-15891 MEDIUM

An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that th…

CVSS 5.3 EPSS 1.09% Sep 26, 2019
CVE-2019-15862 HIGH

An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the a…

CVSS 7.5 EPSS 1.52% Sep 26, 2019
CVE-2015-9349 MEDIUM

The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.

CVSS 6.1 EPSS 0.91% Aug 27, 2019

Showing 1 to 9 CVEs · page 1