Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-59473 SQL Injection vulnerability in the Structure for Admin authenticated user Expressionengine 7.5.14+ Fix from $1,9502026-01-26 MEDIUM 6.1 CVE-2024-38454 ExpressionEngine before 7.4.11 allows XSS. Expressionengine 7.4.11+ Fix from $1,6002024-06-16 HIGH 8.8 CVE-2023-22953 In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user. Expressionengine 7.2.6+ Fix from $1,9502023-02-09 HIGH 7.2 CVE-2020-8242 Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin con… Expressionengine after 5.4.0 Fix from $1,9502022-02-18 CRITICAL 9.8 CVE-2021-33199 In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fix… Expressionengine 6.0.3+ Fix from $2,3002021-08-12 HIGH 8.8 CVE-2021-27230 ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to wri… Expressionengine 5.4.2 / 6.0.3+ Fix from $1,9502021-03-15 HIGH 8.8 CVE-2020-13443 ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Sav… Expressionengine 5.3.2+ Fix from $1,9502020-06-24 MEDIUM 6.1 CVE-2018-17874 ExpressionEngine before 4.3.5 has reflected XSS. Expressionengine 4.3.5+ Fix from $1,6002018-10-01 MEDIUM 5.4 CVE-2017-1000160 EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection Expressionengine Mitigation only Fix from $1,6002017-11-17 HIGH 7.5 CVE-2017-0897 ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can l… Expressionengine Mitigation only Fix from $1,9502017-06-22