CVE-2018-25002: Sunhater Kcfinder
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy.
Affected products
- Sunhater Kcfinder: up to and including 2018-06-01
Published 2021-01-01. Last modified 2026-06-17.