CKSource kayıtları
cksource üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %37,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-23 Relative Path Traversal1
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2019-15862İstismar yok | An issue was discovered in CKFinder through 2.6.2.1.cksource · ckfinder · CWE-434 | Yüksek7,5 | — | %1,5 | 26 Eyl 2019 |
26İzleyin | CVE-2016-20023İstismar yok | In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file wcksource · ckfinder · CWE-23 | Orta6,5 | — | %0,3 | 5 Ara 2025 |
24İzleyin | CVE-2015-9349İstismar yok | The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.cksource · ckeditor · CWE-79 | Orta6,1 | — | %0,9 | 27 Ağu 2019 |
24İzleyin | CVE-2023-4771Kavram kanıtı | Cross-Site Scripting vulnerability in CKSource CKEditorcksource · ckeditor · CWE-79 | Orta6,1 | — | %0,9 | 16 Kas 2023 |
24İzleyin | CVE-2025-63830Kavram kanıtı | CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function.cksource · ckfinder · CWE-79 | Orta6,1 | — | %0,2 | 14 Kas 2025 |
21İzleyin | CVE-2019-15891İstismar yok | An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0.cksource · ckfinder · CWE-200 | Orta5,3 | — | %1,1 | 26 Eyl 2019 |
21İzleyin | CVE-2025-13980İstismar yok | CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-118cksource · ckeditor 5 premium features · CWE-288 | Orta5,3 | — | %0,3 | 28 Oca 2026 |
21İzleyin | CVE-2024-13245İstismar yok | CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009cksource · ckeditor 4 · CWE-79 | Orta5,4 | — | %0,2 | 9 Oca 2025 |
- CVE-2019-1586230İzleyin
An issue was discovered in CKFinder through 2.6.2.1.
YüksekCVSS 7,5İstismar yokEPSS %2cksource · ckfinder26 Eyl 2019
- CVE-2016-2002326İzleyin
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file w
OrtaCVSS 6,5İstismar yokEPSS %0cksource · ckfinder5 Ara 2025
- CVE-2015-934924İzleyin
The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.
OrtaCVSS 6,1İstismar yokEPSS %1cksource · ckeditor27 Ağu 2019
- CVE-2023-477124İzleyin
Cross-Site Scripting vulnerability in CKSource CKEditor
OrtaCVSS 6,1Kavram kanıtıEPSS %1cksource · ckeditor16 Kas 2023
- CVE-2025-6383024İzleyin
CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function.
OrtaCVSS 6,1Kavram kanıtıEPSS %0cksource · ckfinder14 Kas 2025
- CVE-2019-1589121İzleyin
An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0.
OrtaCVSS 5,3İstismar yokEPSS %1cksource · ckfinder26 Eyl 2019
- CVE-2025-1398021İzleyin
CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-118
OrtaCVSS 5,3İstismar yokEPSS %0cksource · ckeditor 5 premium features28 Oca 2026
- CVE-2024-1324521İzleyin
CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009
OrtaCVSS 5,4İstismar yokEPSS %0cksource · ckeditor 49 Oca 2025