Kindsoft's vulnerability footprint centers on KindEditor, a widely embedded web-based rich text editor component used across many content-management and publishing platforms. The product's exposure reflects its role as untrusted user-input processor, with recurring weakness classes including cross-site scripting, cross-site request forgery, and improper authentication that are characteristic of web-facing editor and form-handling components, and the vendor's disclosures tend to acquire public exploit code. Defenders should inventory applications and platforms that bundle this editor component and treat input-sanitization and session-handling updates as priority patches; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kindsoft over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42228HIGH A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html. | Oct 14, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-7543MEDIUM In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability. | Feb 6, 2019 | 6.1 | 25 | NO | YES |
CVE-2021-37267MEDIUM Cross Site Scripting (XSS) vulnerability exists in all versions of KindEditor, which can be exploited by an attacker to obtain user cookie information. | Sep 28, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-30086MEDIUM Cross Site Scripting (XSS) vulnerability exists in KindEditor (Chinese versions) 4.1.12, which can be exploited by an attacker to obtain user cookie information. | Sep 28, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-42227MEDIUM Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this edit | Oct 14, 2021 | 6.1 | 20 | NO | NO |
CVE-2020-28717MEDIUM Cross Site Scripting (XSS) vulnerability in content1 parameter in demo.jsp in kindsoft kindeditor version 4.1.12, allows attackers to execute arbitrary code. | Aug 11, 2023 | 6.1 | 18 | NO | NO |
CVE-2017-1002024MEDIUM Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files. | Sep 14, 2017 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kindsoft.
Media articles that mention a CVE ID that affects a product developed by Kindsoft — matched by CVE ID, not by vendor name.