CVE-2019-19502: Maleck Image Uploader And Browser For Ckeditor
Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.
Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.
Affected products
- Maleck Image Uploader And Browser For Ckeditor: before 4.1.9 (fixed in 4.1.9)
Published 2019-12-02. Last modified 2026-06-17.