Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ez Publish Kernel CRITICAL 9.8
CVE-2020-10806

eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 20…

Fix: 5.4.14.1 / 6.13.6.2+
Fix from $2,300 2020-03-22
Ezplatform Admin Ui MEDIUM 6.1
CVE-2019-12139

An XSS issue was discovered in the Admin UI in eZ Platform 2.x. This affects ezplatform-admin-ui 1.3.x before 1.3.5 and 1.4.x before 1.4.4, and ezpla…

Fix: 1.1.5 / 1.2.4+
Fix from $1,600 2019-05-16
Ez Publish MEDIUM 6.1
CVE-2017-1000431

eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attack…

Fix: after 5.4.9
Fix from $1,600 2018-01-02
Ez Publish HIGH 7.5
CVE-2012-1565

Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 has unknown impact and attack vectors related to an insecure direct object…

Mitigation only
Fix from $1,950 2012-10-06
Ez Publish MEDIUM 6.8
CVE-2012-4053

Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the authenticati…

Mitigation only
Fix from $1,600 2012-07-25
Ez Publish HIGH 7.5
CVE-2010-2672

Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) Section…

Patch available
Fix from $1,950 2010-07-08
Ez Publish HIGH 7.5
CVE-2008-6844

The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows remote at…

Fix: after 3.5.6
Fix from $1,950 2009-07-02
Ez Publish HIGH 10.0
CVE-2007-4493

eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unknown imp…

Fix: after 3.8.8
Fix from $1,950 2007-08-23
Ez Publish MEDIUM 5.0
CVE-2007-4494

The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote attackers to …

Fix: after 3.8.8
Fix from $1,600 2007-08-23
Ez Publish HIGH 9.4
CVE-2005-4853

The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does no…

Mitigation only
Fix from $1,950 2005-12-31
Ez Publish MEDIUM 5.0
CVE-2005-4850

eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers to edit d…

Fix: after 3.7
Fix from $1,600 2005-12-31
Ez Publish MEDIUM 5.0
CVE-2005-4852

The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI to '_' (und…

Fix: 3.5.8+
Fix from $1,600 2005-12-31
Ez Publish MEDIUM 5.0
CVE-2005-4854

eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authenticated user…

Mitigation only
Fix from $1,600 2005-12-31
Ez Publish MEDIUM 5.0
CVE-2005-4856

The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorizatio…

Fix: after 3.8.0
Fix from $1,600 2005-12-31
Ez Publish MEDIUM 6.8
CVE-2003-0310

Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.

Mitigation only
Fix from $1,600 2003-06-16