Cksource / Ckfinder
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2016-20023 | In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided. | MEDIUM | 6.5 | Dec 5, 2025 |
| CVE-2025-63830 | CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content. | MEDIUM | 6.1 | Nov 14, 2025 |
| CVE-2019-15891 | An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that th… | MEDIUM | 5.3 | Sep 26, 2019 |
| CVE-2019-15862 | An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the a… | HIGH | 7.5 | Sep 26, 2019 |
Showing 1 to 4 of 4 CVEs