Maleck develops an image uploader and browser component for CKEditor, a widely used rich-text editor, with the durable signal centered on code-injection vulnerabilities arising from improper control of code generation in the upload and asset-handling pipeline. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maleck over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19502CRITICAL Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code. | Dec 2, 2019 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maleck.
Media articles that mention a CVE ID that affects a product developed by Maleck — matched by CVE ID, not by vendor name.