Known Vulnerabilities for products from Ez

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Ez".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2020-10806 json eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 be... 9.8 - CRITICAL 2020-03-22 2020-03-25
CVE-2019-12139 json An XSS issue was discovered in the Admin UI in eZ Platform 2.x. This affects ezplatform-admin-ui 1.3.x before 1.3.5 and 1.4.x... 6.1 - MEDIUM 2019-05-16 2019-05-17
CVE-2017-1000431 json eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resul... 6.1 - MEDIUM 2018-01-02 2018-01-17
CVE-2012-4053 json Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to... Not Provided 2012-07-25 2026-04-29
CVE-2012-1597 json Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publi... Not Provided 2012-08-17 2026-04-29
CVE-2012-1565 json Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 has unknown impact and attack vectors related to a... Not Provided 2012-10-06 2026-04-29
CVE-2010-2672 json Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL comm... Not Provided 2010-07-08 2026-04-29
CVE-2010-2671 json Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to i... Not Provided 2010-07-08 2026-04-29
CVE-2008-6844 json The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and... Not Provided 2009-07-02 2026-04-23
CVE-2007-4494 json The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which all... Not Provided 2007-08-23 2026-04-23
CVE-2007-4493 json eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy functio... Not Provided 2007-08-23 2026-04-23
CVE-2006-7219 json eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authent... Not Provided 2007-07-06 2026-04-23
CVE-2006-7218 json eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languag... Not Provided 2007-07-06 2026-04-23
CVE-2006-0938 json Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web scri... Not Provided 2006-03-01 2025-04-03
CVE-2005-4857 json eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to... Not Provided 2005-12-31 2025-04-03
CVE-2005-4856 json The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not prop... Not Provided 2005-12-31 2025-04-03
CVE-2005-4855 json Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before ... Not Provided 2005-12-31 2025-04-03
CVE-2005-4854 json eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows r... Not Provided 2005-12-31 2025-04-03
CVE-2005-4853 json The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8... Not Provided 2005-12-31 2025-04-03
CVE-2005-4852 json The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric charact... Not Provided 2005-12-31 2025-04-03

Known software with vulnerabilities from Ez

Type Vendor Product Version
ApplicationEzEzplatform-admin-ui1.3.0
ApplicationEzEzplatform-page-builder1.1.0
ApplicationEzEz Publish2.9-3

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report