References https://www.cnvd.org.cn/flaw/show/CNVD-2019-07933 https://blog.csdn.net/bluemoon_0/article/details/129483324 https://cloud.tencent.com/developer/article/2200011 https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/others/Ueditor-%E7%BC%96%E8%BE%91%E5%99%A8%E6%BC%8F%E6%B4%9E%E6%80%BB%E7%BB%93.md https://bbs.huaweicloud.com/blogs/406031 https://www.cnblogs.com/zhibing/p/16893839.html
Related Vulnerabilitiestianti /tianti-module-admin/ueditor/controller.jsp 服务器端请求伪造漏洞DoraCMS /api/v1/upload/ueditor 服务器端请求伪造漏洞(CVE-2026-25870)PoCCNVD-2017-20077: Ueditor编辑器.net版本存在文件上传漏洞PoCueditor-file-upload: UEditor - Arbitrary File UploadPoCueditor-arbitrary-file-upload: UEditor - PHP Arbitrary File UploadPoCueditor-ssrf: UEditor - Server Side Request ForgeryPoCueditor-xss: ueditor - Cross Site Scripting明腾CMS /mingteng/ueditor/imageup/savePath/public/upload/temp/pictitle/banner/dir/images.html 文件上传漏洞朗速ERP UEditorAjaxApi 接口UEditor任意文件上传漏洞朗速ERP UEditorAjaxApi存在SSRF漏洞易思软件智能物流无人值守系统 ueditor 任意文件上传漏洞百度 UEditor .net版本 /net/controller.ashx 文件上传漏洞