VendorsCKSourceckfinderall versions
Vulnerabilities

CKSource CKFinder

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2019-15862
An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP, CKFinder for ASP.NET, CKFinder for ColdFusion, and CKFinder for PHP.
Published 2019-09-26 · Modified
7.5EPSS 0.015
CVE-2016-20023
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.
Published 2025-12-05 · Analyzed
6.5EPSS 0.003
CVE-2025-63830
CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.
Published 2025-11-14 · Analyzed
6.1EPSS 0.002
CVE-2019-15891
An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof content sniffing protection.
Published 2019-09-26 · Modified
5.3EPSS 0.011