episerver records
6 published records for vendor episerver.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-269 Improper Privilege Management1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-611 Improper Restriction of XML External Entity Reference1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2018-12596Proof of concept | Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspxepiserver · ektron cms · CWE-269 | Critical9.8 | — | 22.4% | Oct 10, 2018 |
31Monitor | CVE-2017-17762Proof of concept | XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTDepiserver · episerver · CWE-611 | High7.5 | — | 4.6% | Aug 29, 2018 |
25Monitor | CVE-2020-24550Proof of concept | An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirecepiserver · find · CWE-601 | Medium6.1 | — | 4.7% | Mar 31, 2021 |
24Monitor | CVE-2012-1031No exploit | Unspecified vulnerability in EPiServer CMS 5 and 6 through 6R2, in certain configurations using Forms Authentication, allows remote authentiepiserver · episerver cms | Medium6.0 | — | 1.0% | Feb 8, 2012 |
17Monitor | CVE-2012-1032No exploit | Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker module 3.x before 3.4.5 for EPiServer allows remote attackers to inject siteseeker · euroling siteseeker · CWE-79 | Medium4.3 | — | 1.2% | Sep 17, 2014 |
17Monitor | CVE-2012-1034No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the admin interface in EPiServer CMS through 6R2 allow remote attackers to inject arbepiserver · episerver cms · CWE-79 | Medium4.3 | — | 1.1% | Feb 8, 2012 |
- CVE-2018-1259646Plan
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx
CriticalCVSS 9.8Proof of conceptEPSS 22%episerver · ektron cmsOct 10, 2018
- CVE-2017-1776231Monitor
XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD
HighCVSS 7.5Proof of conceptEPSS 5%episerver · episerverAug 29, 2018
- CVE-2020-2455025Monitor
An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirec
MediumCVSS 6.1Proof of conceptEPSS 5%episerver · findMar 31, 2021
- CVE-2012-103124Monitor
Unspecified vulnerability in EPiServer CMS 5 and 6 through 6R2, in certain configurations using Forms Authentication, allows remote authenti
MediumCVSS 6.0No exploitEPSS 1%episerver · episerver cmsFeb 8, 2012
- CVE-2012-103217Monitor
Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker module 3.x before 3.4.5 for EPiServer allows remote attackers to inject
MediumCVSS 4.3No exploitEPSS 1%siteseeker · euroling siteseekerSep 17, 2014
- CVE-2012-103417Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the admin interface in EPiServer CMS through 6R2 allow remote attackers to inject arb
MediumCVSS 4.3No exploitEPSS 1%episerver · episerver cmsFeb 8, 2012