Vulnerabilities > Kindsoft

DATE CVE VULNERABILITY TITLE RISK
2023-08-11 CVE-2020-28717 Cross-site Scripting vulnerability in Kindsoft Kindeditor 4.1.12
Cross Site Scripting (XSS) vulnerability in content1 parameter in demo.jsp in kindsoft kindeditor version 4.1.12, allows attackers to execute arbitrary code.
network
low complexity
kindsoft CWE-79
6.1
2021-10-14 CVE-2021-42227 Cross-site Scripting vulnerability in Kindsoft Kindeditor
Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).
network
low complexity
kindsoft CWE-79
6.1
2021-10-14 CVE-2021-42228 Cross-Site Request Forgery (CSRF) vulnerability in Kindsoft Kindeditor
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.
network
low complexity
kindsoft CWE-352
8.8
2021-09-28 CVE-2021-30086 Cross-site Scripting vulnerability in Kindsoft Kindeditor 4.1.12
Cross Site Scripting (XSS) vulnerability exists in KindEditor (Chinese versions) 4.1.12, which can be exploited by an attacker to obtain user cookie information.
network
low complexity
kindsoft CWE-79
6.1
2021-09-28 CVE-2021-37267 Cross-site Scripting vulnerability in Kindsoft Kindeditor
Cross Site Scripting (XSS) vulnerability exists in all versions of KindEditor, which can be exploited by an attacker to obtain user cookie information.
network
low complexity
kindsoft CWE-79
6.1
2019-02-06 CVE-2019-7543 Cross-site Scripting vulnerability in Kindsoft Kindeditor 4.1.11
In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability.
network
low complexity
kindsoft CWE-79
6.1
2017-09-14 CVE-2017-1002024 Improper Authentication vulnerability in Kindsoft Kind Editor and Kindeditor
Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files.
network
low complexity
kindsoft CWE-287
4.3