VYPR
Vendor

Cfmsource

Products
12
CVEs
14
Across products
15
Status
Private

Products

12

Recent CVEs

14
  • CVE-2011-4972HigNov 13, 2019
    risk 0.49cvss 7.5epss 0.02

    hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.

  • CVE-2019-15862HigSep 26, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP,…

  • CVE-2025-63830MedNov 14, 2025
    risk 0.40cvss 6.1epss 0.00

    CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

  • CVE-2015-9349MedAug 27, 2019
    risk 0.40cvss 6.1epss 0.01

    The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.

  • CVE-2024-13245MedJan 9, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.

  • CVE-2019-15891MedSep 26, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof content sniffing protection.

  • CVE-2025-13980MedJan 28, 2026
    risk 0.34cvss 5.3epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before…

  • CVE-2016-20023MedDec 5, 2025
    risk 0.33cvss 5.0epss 0.00

    In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

  • CVE-2023-4771MedNov 16, 2023
    risk 0.33cvss 6.1epss 0.01

    A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.

  • CVE-2008-6324Feb 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.

  • CVE-2008-6323Feb 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in forummessages.cfm in CFMSource CF_Auction allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.

  • CVE-2008-6322Feb 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.

  • CVE-2008-6319Feb 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in calendarevent.cfm in CF_Calendar allows remote attackers to execute arbitrary SQL commands via the calid parameter.

  • CVE-2014-4037Jun 11, 2014
    risk 0.00cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor before 2.6.11 and earlier allows remote attackers to inject arbitrary web script or HTML via an array key in the textinputs[] parameter, a…