CVE-2025-30580: Kellydiek Digiwidgets Image Editor
Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.
Improper Control of Generation of Code ('Code Injection') vulnerability in kellydiek DigiWidgets Image Editor digiwidgets-image-editor allows Remote Code Inclusion.This issue affects DigiWidgets Image Editor: from n/a through <= 1.10.
Affected products
- Kellydiek Digiwidgets Image Editor: up to and including 1.10
Published 2025-04-01. Last modified 2026-06-17.