Medium severity5.3NVD Advisory· Published Jul 26, 2019· Updated Jun 17, 2026
CVE-2019-14280
CVE-2019-14280
Description
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Craft/Craftdescription
Patches
Vulnerability mechanics
References
3- github.com/craftcms/cms/blob/develop-v2/CHANGELOG-v2.mdnvdRelease NotesThird Party Advisory
- github.com/craftcms/cms/blob/develop/CHANGELOG-v3.mdnvdRelease NotesThird Party Advisory
- packetstormsecurity.com/files/154276/Craft-CMS-2.7.9-3.2.5-Information-Disclosure.htmlnvd
News mentions
0No linked articles in our index yet.