CVE-2019-15891: Cksource Ckfinder
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof content sniffing protection.
Affected products
- Cksource Ckfinder: up to and including 2.6.2.1; from 3.0, up to and including 3.5.0
Published 2019-09-26. Last modified 2026-06-17.