Vulnerabilities > EZ
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-03-22 | CVE-2020-10806 | Unrestricted Upload of File with Dangerous Type vulnerability in EZ Publish-Kernel and EZ Publish-Legacy eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. | 9.8 |
2019-05-16 | CVE-2019-12139 | Cross-site Scripting vulnerability in EZ Ezplatform-Admin-Ui and Ezplatform-Page-Builder An XSS issue was discovered in the Admin UI in eZ Platform 2.x. | 6.1 |
2018-01-02 | CVE-2017-1000431 | Cross-site Scripting vulnerability in EZ Publish eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. | 6.1 |