FCKeditor is a legacy web-based rich-text editor component that achieved broad embedding across content management systems and web applications, positioning it prominently in the vulnerability landscape despite its narrow product scope. Vulnerabilities affecting the editor recur through input-handling and code-generation weaknesses—notably cross-site scripting, code injection, and path traversal—that are characteristic of user-facing HTML editing surfaces, and public exploit code for these classes has been widely available. Defenders should treat this vendor's advisories as high-priority for any system still running or bundling the editor; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fckeditor over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2265HIGH Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequence | Jul 5, 2009 | 7.5 | 85 | NO | YES |
CVE-2008-6178HIGH Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke ET, and other products, allow | Feb 19, 2009 | 7.5 | 33 | NO | YES |
CVE-2006-0658MEDIUM Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script fil | Feb 13, 2006 | 5.0 | 25 | NO | YES |
CVE-2005-0613MEDIUM Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files. | Feb 28, 2005 | 5.0 | 24 | NO | YES |
CVE-2009-2324MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTML via components in the samples (aka _sa | Jul 5, 2009 | 4.3 | 17 | NO | NO |
CVE-2006-0921MEDIUM Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directori | Feb 28, 2006 | 6.4 | 17 | NO | NO |
CVE-2006-2529MEDIUM editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to uplo | May 22, 2006 | 5.0 | 16 | NO | NO |
CVE-2006-6978MEDIUM Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) hr | Feb 8, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fckeditor.
Media articles that mention a CVE ID that affects a product developed by Fckeditor — matched by CVE ID, not by vendor name.