CVE-2025-30580: Kellydiek Digiwidgets Image Editor

Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper Control of Generation of Code ('Code Injection') vulnerability in kellydiek DigiWidgets Image Editor digiwidgets-image-editor allows Remote Code Inclusion.This issue affects DigiWidgets Image Editor: from n/a through <= 1.10.

Affected products

  • Kellydiek Digiwidgets Image Editor: up to and including 1.10

Published 2025-04-01. Last modified 2026-06-17.