Vulnerabilities > EZ

DATE CVE VULNERABILITY TITLE RISK
2020-03-22 CVE-2020-10806 Unrestricted Upload of File with Dangerous Type vulnerability in EZ Publish-Kernel and EZ Publish-Legacy
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution.
network
low complexity
ez CWE-434
critical
9.8
2019-05-16 CVE-2019-12139 Cross-site Scripting vulnerability in EZ Ezplatform-Admin-Ui and Ezplatform-Page-Builder
An XSS issue was discovered in the Admin UI in eZ Platform 2.x.
network
low complexity
ez CWE-79
6.1
2018-01-02 CVE-2017-1000431 Cross-site Scripting vulnerability in EZ Publish
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g.
network
low complexity
ez CWE-79
6.1