Vulnerabilities > Ibexa > EZ Platform Kernel

DATE CVE VULNERABILITY TITLE RISK
2023-03-12 CVE-2021-46875 Cross-site Scripting vulnerability in Ibexa EZ Platform Kernel
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1.
network
low complexity
ibexa CWE-79
6.1
2023-03-12 CVE-2021-46876 Unspecified vulnerability in Ibexa EZ Platform Kernel
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1.
network
low complexity
ibexa
5.3
2023-03-12 CVE-2022-48365 Improper Privilege Management vulnerability in Ibexa Digital Experience Platform and EZ Platform Kernel
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26.
network
low complexity
ibexa CWE-269
7.2
2023-03-12 CVE-2022-48366 Race Condition vulnerability in Ibexa products
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19.
network
high complexity
ibexa CWE-362
3.7
2023-03-12 CVE-2022-48367 Missing Authorization vulnerability in Ibexa products
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28.
network
low complexity
ibexa CWE-862
critical
9.8
2022-02-18 CVE-2022-25336 Authorization Bypass Through User-Controlled Key vulnerability in Ibexa EZ Platform Kernel
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.
network
low complexity
ibexa CWE-639
5.3
2022-02-18 CVE-2022-25337 Injection vulnerability in Ibexa EZ Platform Kernel
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.
network
ibexa CWE-74
6.8