CVE-2019-14280: Craft CMS
Medium severity, CVSS 5.3. EPSS: 9.4% chance of exploitation in the next 30 days.
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
Affected products
- Craft CMS Craft CMS: from 2.0.2524, before 2.7.10 (fixed in 2.7.10); from 3.0.0, before 3.2.6 (fixed in 3.2.6)
Published 2019-07-26. Last modified 2026-06-17.