CKSource develops web-based rich-text editing and file-management solutions—CKEditor and CKFinder—that are embedded across content-management and publishing platforms. Its vulnerability profile centers on input-handling and access-control weaknesses inherent to client-side editors and server-side file operations, particularly cross-site scripting, authentication bypass, path traversal, and information disclosure. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cksource over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15862HIGH An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was config | Sep 26, 2019 | 7.5 | 24 | NO | NO |
CVE-2016-20023MEDIUM In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided. | Dec 5, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-63830MEDIUM CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content. | Nov 14, 2025 | 6.1 | 21 | NO | NO |
CVE-2019-15891MEDIUM An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a b | Sep 26, 2019 | 5.3 | 20 | NO | NO |
CVE-2025-13980MEDIUM Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Featu | Jan 28, 2026 | 5.3 | 19 | NO | NO |
CVE-2023-4771MEDIUM A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckedit | Nov 16, 2023 | 6.1 | 17 | NO | NO |
CVE-2015-9349MEDIUM The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser. | Aug 27, 2019 | 6.1 | 17 | NO | NO |
CVE-2024-13245MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS). | Jan 9, 2025 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cksource.
Media articles that mention a CVE ID that affects a product developed by Cksource — matched by CVE ID, not by vendor name.