Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2025-59473
SQL Injection vulnerability in the Structure for Admin authenticated user
Expressionengine
7.5.14+
MEDIUM 6.1
CVE-2024-38454
ExpressionEngine before 7.4.11 allows XSS.
Expressionengine
7.4.11+
HIGH 8.8
CVE-2023-22953
In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user.
Expressionengine
7.2.6+
HIGH 7.2
CVE-2020-8242
Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin con…
Expressionengine
after 5.4.0
CRITICAL 9.8
CVE-2021-33199
In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fix…
Expressionengine
6.0.3+
HIGH 8.8
CVE-2021-27230
ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to wri…
Expressionengine
5.4.2 / 6.0.3+
HIGH 8.8
CVE-2020-13443
ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Sav…
Expressionengine
5.3.2+
MEDIUM 6.1
CVE-2018-17874
ExpressionEngine before 4.3.5 has reflected XSS.
Expressionengine
4.3.5+
MEDIUM 5.4
CVE-2017-1000160
EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection
Expressionengine
Mitigation only
HIGH 7.5
CVE-2017-0897
ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can l…
Expressionengine
Mitigation only