Known Vulnerabilities for products from Ez
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Ez".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-10806 json | eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 be... | 9.8 - CRITICAL | 2020-03-22 | 2020-03-25 |
| CVE-2019-12139 json | An XSS issue was discovered in the Admin UI in eZ Platform 2.x. This affects ezplatform-admin-ui 1.3.x before 1.3.5 and 1.4.x... | 6.1 - MEDIUM | 2019-05-16 | 2019-05-17 |
| CVE-2017-1000431 json | eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resul... | 6.1 - MEDIUM | 2018-01-02 | 2018-01-17 |
| CVE-2012-4053 json | Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to... | Not Provided | 2012-07-25 | 2026-04-29 |
| CVE-2012-1597 json | Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publi... | Not Provided | 2012-08-17 | 2026-04-29 |
| CVE-2012-1565 json | Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 has unknown impact and attack vectors related to a... | Not Provided | 2012-10-06 | 2026-04-29 |
| CVE-2010-2672 json | Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL comm... | Not Provided | 2010-07-08 | 2026-04-29 |
| CVE-2010-2671 json | Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to i... | Not Provided | 2010-07-08 | 2026-04-29 |
| CVE-2008-6844 json | The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and... | Not Provided | 2009-07-02 | 2026-04-23 |
| CVE-2007-4494 json | The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which all... | Not Provided | 2007-08-23 | 2026-04-23 |
| CVE-2007-4493 json | eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy functio... | Not Provided | 2007-08-23 | 2026-04-23 |
| CVE-2006-7219 json | eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authent... | Not Provided | 2007-07-06 | 2026-04-23 |
| CVE-2006-7218 json | eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languag... | Not Provided | 2007-07-06 | 2026-04-23 |
| CVE-2006-0938 json | Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web scri... | Not Provided | 2006-03-01 | 2025-04-03 |
| CVE-2005-4857 json | eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to... | Not Provided | 2005-12-31 | 2025-04-03 |
| CVE-2005-4856 json | The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not prop... | Not Provided | 2005-12-31 | 2025-04-03 |
| CVE-2005-4855 json | Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before ... | Not Provided | 2005-12-31 | 2025-04-03 |
| CVE-2005-4854 json | eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows r... | Not Provided | 2005-12-31 | 2025-04-03 |
| CVE-2005-4853 json | The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8... | Not Provided | 2005-12-31 | 2025-04-03 |
| CVE-2005-4852 json | The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric charact... | Not Provided | 2005-12-31 | 2025-04-03 |
Known software with vulnerabilities from Ez
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Ez | Ezplatform-admin-ui | 1.3.0 |
| Application | Ez | Ezplatform-page-builder | 1.1.0 |
| Application | Ez | Ez Publish | 2.9-3 |