Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ckeditor 5 Premium Features MEDIUM 5.3
CVE-2025-13980

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue a…

Fix: 1.2.10 / 1.3.6+
Fix from $1,600 2026-01-28
Ckfinder MEDIUM 6.5
CVE-2016-20023

In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provid…

Fix: 2.5.0.1+
Fix from $1,600 2025-12-05
Ckfinder MEDIUM 6.1
CVE-2025-63830

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active conten…

No fix yet
Fix from $1,600 2025-11-14
Ckeditor 4 MEDIUM 5.4
CVE-2024-13245

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor all…

Mitigation only
Fix from $1,600 2025-01-09
Ckeditor MEDIUM 6.1
CVE-2023-4771

A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious java…

Fix: after 4.15.1
Fix from $1,600 2023-11-16
Ckfinder HIGH 7.5
CVE-2019-15862

An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (eve…

Fix: 2.6.3+
Fix from $1,950 2019-09-26
Ckfinder MEDIUM 5.3
CVE-2019-15891

An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusi…

Fix: after 3.5.0
Fix from $1,600 2019-09-26
Ckeditor MEDIUM 6.1
CVE-2015-9349

The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.

Fix: 4.5.3.1+
Fix from $1,600 2019-08-27