Skip to content
Noroxi

CKSource records

8 published records for vendor cksource.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
37.5%
Median publish → KEV
No record has entered KEV

All records

8 records
  • An issue was discovered in CKFinder through 2.6.2.1.

    HighCVSS 7.5No exploitEPSS 2%

    cksource · ckfinderSep 26, 2019

  • In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file w

    MediumCVSS 6.5No exploitEPSS 0%

    cksource · ckfinderDec 5, 2025

  • CVE-2015-9349
    24Monitor

    The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.

    MediumCVSS 6.1No exploitEPSS 1%

    cksource · ckeditorAug 27, 2019

  • CVE-2023-4771
    24Monitor

    Cross-Site Scripting vulnerability in CKSource CKEditor

    MediumCVSS 6.1Proof of conceptEPSS 1%

    cksource · ckeditorNov 16, 2023

  • CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function.

    MediumCVSS 6.1Proof of conceptEPSS 0%

    cksource · ckfinderNov 14, 2025

  • An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0.

    MediumCVSS 5.3No exploitEPSS 1%

    cksource · ckfinderSep 26, 2019

  • CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-118

    MediumCVSS 5.3No exploitEPSS 0%

    cksource · ckeditor 5 premium featuresJan 28, 2026

  • CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009

    MediumCVSS 5.4No exploitEPSS 0%

    cksource · ckeditor 4Jan 9, 2025