VYPR
Medium severity5.3NVD Advisory· Published Jul 26, 2019· Updated Jun 17, 2026

CVE-2019-14280

CVE-2019-14280

Description

In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
    Range: >=2.0.2524,<2.7.10
  • Craft/Craftdescription
  • Craftcms/CMSllm-fuzzy
    Range: <2.7.10, <3.2.6

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.