Vulnerabilidades em CKSource
3 resultadosAnálise Vexday
CKSource apresenta footprint reduzido com apenas 3 CVEs registradas, nenhuma em exploração ativa ou crítica. A vulnerabilidade dominante (CWE-23: Path Traversal) é de moderada complexidade, e a ausência de publicações recentes sugere que o risco é estável e não apresenta dinâmica de ataque contemporânea.
CVE-2011-4972—hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackeEPSS 1.7%CVE-2023-4771MEDIUMCross-Site Scripting vulnerability in CKSource CKEditorEPSS 0.9%CVE-2016-20023MEDIUMIn CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file wEPSS 0.3%