CVE-2018-25002: Sunhater Kcfinder

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy.

Affected products

  • Sunhater Kcfinder: up to and including 2018-06-01

Published 2021-01-01. Last modified 2026-06-17.