CVE-2019-19502

CRITICAL

CKEditor <4.1.9 - Code Injection

Title source: llm
STIX 2.1

Description

Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.

Scores

CVSS v3 9.8
EPSS 0.0085
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
maleck/image_uploader_and_browser_for_ckeditor < 4.1.9
Published Dec 02, 2019
Tracked Since Feb 18, 2026