Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2023-4771

Disclosure Date: November 16, 2023 (last updated November 29, 2023)
A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.
Attacker Value
Unknown

CVE-2019-15862

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP, CKFinder for ASP.NET, CKFinder for ColdFusion, and CKFinder for PHP.
Attacker Value
Unknown

CVE-2019-15891

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof content sniffing protection.
Attacker Value
Unknown

CVE-2015-9349

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.
0