Cksource
2 CVEs tracked since 2019. Since Sep 2019, none of them reached CISA KEV.
Cksource CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2019-09 | 2 | 0 |
Products
The products that kept showing up in Cksource's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 9 most recently published vulnerabilities affecting Cksource.
- CVE-2025-13980CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-1185.3
- CVE-2016-20023In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.5.0
- CVE-2025-63830CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.6.1
- CVE-2024-13245CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-0095.4
- CVE-2023-4771Cross-Site Scripting vulnerability in CKSource CKEditor6.1
- CVE-2011-4972hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.7.5
- CVE-2019-15891An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletpro...5.3
- CVE-2019-15862An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept fi...7.5
- CVE-2015-9349The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.6.1
The record
- Peak rank
- #142 in Sep 2019
- Busiest month shown
- Sep 2019, 2 CVEs
- Months with a KEV entry
- 0 since Sep 2019
- Monthly snapshots
- 1 since 2019