Skip to content
Noroxi

kindsoft records

7 published records for vendor kindsoft.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17
  2. 19
  3. 21
  4. 23

Bar: total · dark part: CISA KEV.

All records

7 records
  • A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.

    HighCVSS 8.8No exploitEPSS 1%

    kindsoft · kindeditorOct 14, 2021

  • CVE-2019-7543
    25Monitor

    In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability.

    MediumCVSS 6.1Proof of conceptEPSS 3%

    kindsoft · kindeditorFeb 6, 2019

  • Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html

    MediumCVSS 6.1No exploitEPSS 1%

    kindsoft · kindeditorOct 14, 2021

  • Cross Site Scripting (XSS) vulnerability exists in KindEditor (Chinese versions) 4.1.12, which can be exploited by an attacker to obtain use

    MediumCVSS 6.1No exploitEPSS 1%

    kindsoft · kindeditorSep 28, 2021

  • Cross Site Scripting (XSS) vulnerability exists in all versions of KindEditor, which can be exploited by an attacker to obtain user cookie i

    MediumCVSS 6.1No exploitEPSS 1%

    kindsoft · kindeditorSep 28, 2021

  • Cross Site Scripting (XSS) vulnerability in content1 parameter in demo.jsp in kindsoft kindeditor version 4.1.12, allows attackers to execut

    MediumCVSS 6.1No exploitEPSS 1%

    kindsoft · kindeditorAug 11, 2023

  • Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upl

    MediumCVSS 4.3No exploitEPSS 1%

    kindsoft · kind editorSep 14, 2017