Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ez ez publish vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2020-23065
Cross Site Scripting vulnerabiltiy in eZ Systems AS eZPublish Platform v.5.4 and eZ Publish Legacy v.5.4 allows a remote authenticated malicious user to execute arbitrary code via the video-js.swf.
Ibexa Ezpublish Legacy 5.4
Ibexa Ezpublish Platform 5.4
9.8
CVSSv3
CVE-2022-48367
An issue exists in eZ Publish Ibexa Kernel prior to 7.5.28. Access control based on object state is mishandled.
Ibexa Kernel
Ibexa Digital Experience Platform
Ibexa Ez Platform Kernel
Ibexa Fastly
Ibexa Ezplatform-http-cache-fastly
5.3
CVSSv3
CVE-2021-46876
An issue exists in eZ Publish Ibexa Kernel prior to 7.5.15.1. The /user/sessions endpoint can be abused to determine account existence.
Ibexa Ez Platform Kernel
7.5
CVSSv3
CVE-2015-10071
A vulnerability was found in gitter-badger ezpublish-modern-legacy. It has been rated as problematic. This issue affects some unknown processing of the file kernel/user/forgotpassword.php. The manipulation leads to weak password recovery. The complexity of an attack is rather hig...
Gitter Ez Publish Modern Legacy
9.8
CVSSv3
CVE-2020-10806
eZ Publish Kernel prior to 5.4.14.1, 6.x prior to 6.13.6.2, and 7.x prior to 7.5.6.2 and eZ Publish Legacy prior to 5.4.14.1, 2017 prior to 2017.12.7.2, and 2019 prior to 2019.03.4.2 allow remote malicious users to execute arbitrary code by uploading PHP code, unless the vhost co...
Ez Ez Publish-kernel
Ez Ez Publish-legacy
9.8
CVSSv3
CVE-2014-2552
Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote malicious users to gain access to sensitive data.
Brookinsconsulting Collected Information Export 1.1.0
6.1
CVSSv3
CVE-2017-1000431
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.
Ez Ez Publish
NA
CVE-2012-1565
Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 has unknown impact and attack vectors related to an insecure direct object reference.
Ez Ez Publish 4.6.0
Ez Ez Publish 4.2.0
Ez Ez Publish 4.3.0
Ez Ez Publish 4.4.0
Ez Ez Publish 4.5.0
Ez Ez Publish 4.1.4
NA
CVE-2012-1597
Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish prior to 1.5 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Ez Ezjscore 1.0
Ez Ezjscore
1 EDB exploit
NA
CVE-2012-4053
Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 up to and including 4.6 allows remote malicious users to hijack the authentication of unspecified victims via unknown vectors.
Ez Ez Publish 4.1.0
Ez Ez Publish 4.2.0
Ez Ez Publish 4.3.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »