Vulnerabilities (CVE)

Filtered by vendor Sunhater Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-14315 1 Sunhater 1 Kcfinder 2019-12-10 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier allows remote attackers to inject arbitrary web script or HTML via the CKEditorFuncNum parameter.