Sunhater's vulnerability footprint centers on KCFinder, a file-manager component commonly embedded in web applications and content-management systems. The recurring exposure involves application-layer input-handling issues, specifically cross-site scripting and improper input validation, typical of web-facing utility code where sanitization and encoding boundaries are frequently overlooked.
The number and severity of CVEs published that impact products developed by Sunhater over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-25002HIGH uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's securit | Jan 1, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-14315MEDIUM A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier allows remote attackers to inject arbitrary web script or HT | Jul 28, 2019 | 6.1 | 21 | NO | NO |
CVE-2014-3988MEDIUM Cross-site scripting (XSS) vulnerability in index.php in SunHater KCFinder 3.11 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) file or (2) direc | Dec 3, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sunhater.
Media articles that mention a CVE ID that affects a product developed by Sunhater — matched by CVE ID, not by vendor name.