CVE-2019-13187: Symphonyextensions Rich Text Formatter
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.
Affected products
- Symphonyextensions Rich Text Formatter: up to and including 1.1.1
Published 2019-09-05. Last modified 2026-06-17.