CKSource records
8 published records for vendor cksource.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 37.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-23 Relative Path Traversal1
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2019-15862No exploit | An issue was discovered in CKFinder through 2.6.2.1.cksource · ckfinder · CWE-434 | High7.5 | — | 1.5% | Sep 26, 2019 |
26Monitor | CVE-2016-20023No exploit | In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file wcksource · ckfinder · CWE-23 | Medium6.5 | — | 0.3% | Dec 5, 2025 |
24Monitor | CVE-2015-9349No exploit | The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.cksource · ckeditor · CWE-79 | Medium6.1 | — | 0.9% | Aug 27, 2019 |
24Monitor | CVE-2023-4771Proof of concept | Cross-Site Scripting vulnerability in CKSource CKEditorcksource · ckeditor · CWE-79 | Medium6.1 | — | 0.9% | Nov 16, 2023 |
24Monitor | CVE-2025-63830Proof of concept | CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function.cksource · ckfinder · CWE-79 | Medium6.1 | — | 0.2% | Nov 14, 2025 |
21Monitor | CVE-2019-15891No exploit | An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0.cksource · ckfinder · CWE-200 | Medium5.3 | — | 1.1% | Sep 26, 2019 |
21Monitor | CVE-2025-13980No exploit | CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-118cksource · ckeditor 5 premium features · CWE-288 | Medium5.3 | — | 0.3% | Jan 28, 2026 |
21Monitor | CVE-2024-13245No exploit | CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009cksource · ckeditor 4 · CWE-79 | Medium5.4 | — | 0.2% | Jan 9, 2025 |
- CVE-2019-1586230Monitor
An issue was discovered in CKFinder through 2.6.2.1.
HighCVSS 7.5No exploitEPSS 2%cksource · ckfinderSep 26, 2019
- CVE-2016-2002326Monitor
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file w
MediumCVSS 6.5No exploitEPSS 0%cksource · ckfinderDec 5, 2025
- CVE-2015-934924Monitor
The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.
MediumCVSS 6.1No exploitEPSS 1%cksource · ckeditorAug 27, 2019
- CVE-2023-477124Monitor
Cross-Site Scripting vulnerability in CKSource CKEditor
MediumCVSS 6.1Proof of conceptEPSS 1%cksource · ckeditorNov 16, 2023
- CVE-2025-6383024Monitor
CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function.
MediumCVSS 6.1Proof of conceptEPSS 0%cksource · ckfinderNov 14, 2025
- CVE-2019-1589121Monitor
An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0.
MediumCVSS 5.3No exploitEPSS 1%cksource · ckfinderSep 26, 2019
- CVE-2025-1398021Monitor
CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-118
MediumCVSS 5.3No exploitEPSS 0%cksource · ckeditor 5 premium featuresJan 28, 2026
- CVE-2024-1324521Monitor
CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009
MediumCVSS 5.4No exploitEPSS 0%cksource · ckeditor 4Jan 9, 2025