VYPR
Vendor

Cfmsource

Products
12
CVEs
15
Across products
16
Status
Private

Products

12

Recent CVEs

15
  • CVE-2011-4972HigNov 13, 2019
    risk 0.49cvss 7.5epss 0.02

    hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.

  • CVE-2019-15862HigSep 26, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP,…

  • CVE-2022-48110MedFeb 13, 2023
    risk 0.43cvss 6.1epss 0.02

    CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation discusses that it is the responsibility of an…

  • CVE-2025-63830MedNov 14, 2025
    risk 0.40cvss 6.1epss 0.00

    CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

  • CVE-2015-9349MedAug 27, 2019
    risk 0.40cvss 6.1epss 0.01

    The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.

  • CVE-2024-13245MedJan 9, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.

  • CVE-2019-15891MedSep 26, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof content sniffing protection.

  • CVE-2025-13980MedJan 28, 2026
    risk 0.34cvss 5.3epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before…

  • CVE-2016-20023MedDec 5, 2025
    risk 0.33cvss 5.0epss 0.00

    In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

  • CVE-2023-4771MedNov 16, 2023
    risk 0.33cvss 6.1epss 0.01

    A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.

  • CVE-2008-6324Feb 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.

  • CVE-2008-6323Feb 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in forummessages.cfm in CFMSource CF_Auction allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.

  • CVE-2008-6322Feb 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.

  • CVE-2008-6319Feb 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in calendarevent.cfm in CF_Calendar allows remote attackers to execute arbitrary SQL commands via the calid parameter.

  • CVE-2014-4037Jun 11, 2014
    risk 0.00cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor before 2.6.11 and earlier allows remote attackers to inject arbitrary web script or HTML via an array key in the textinputs[] parameter, a…