Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fckeditor

First CVE: Feb 28, 2005Active for: 21 yearsTotal CVEs: 8

FCKeditor is a legacy web-based rich-text editor component that achieved broad embedding across content management systems and web applications, positioning it prominently in the vulnerability landscape despite its narrow product scope. Vulnerabilities affecting the editor recur through input-handling and code-generation weaknesses—notably cross-site scripting, code injection, and path traversal—that are characteristic of user-facing HTML editing surfaces, and public exploit code for these classes has been widely available. Defenders should treat this vendor's advisories as high-priority for any system still running or bundling the editor; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fckeditor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 28, 2005
21 years ago
Most Recent CVE
Jul 5, 2009
6,228 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-2265HIGH
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequence
Jul 5, 20097.585NOYES
CVE-2008-6178HIGH
Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke ET, and other products, allow
Feb 19, 20097.533NOYES
CVE-2006-0658MEDIUM
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script fil
Feb 13, 20065.025NOYES
CVE-2005-0613MEDIUM
Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.
Feb 28, 20055.024NOYES
CVE-2009-2324MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTML via components in the samples (aka _sa
Jul 5, 20094.317NONO
CVE-2006-0921MEDIUM
Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directori
Feb 28, 20066.417NONO
CVE-2006-2529MEDIUM
editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to uplo
May 22, 20065.016NONO
CVE-2006-6978MEDIUM
Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) hr
Feb 8, 20074.314NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
75%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
12.5% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
50.0% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fckeditor.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fckeditor — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fckeditor's Products

View all 1 CNAs →

Top CWEs