ez records
23 published records for vendor ez.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 13%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-399 Resource Management Errors1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-19 Data Processing Errors1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2007-4493No exploit | eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unez · ez publish | Critical10.0 | — | 1.8% | Aug 22, 2007 |
40Plan | CVE-2020-10806No exploit | eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.ez · ez publish-kernel · CWE-434 | Critical9.8 | — | 2.3% | Mar 22, 2020 |
37Monitor | CVE-2005-4853No exploit | The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 2005081ez · ez publish · CWE-264 | Critical9.4 | — | 1.5% | Dec 31, 2005 |
31Monitor | CVE-2008-6844Proof of concept | The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows ez · ez publish · CWE-264 | High7.5 | — | 3.0% | Jul 2, 2009 |
31Monitor | CVE-2012-1565No exploit | Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 has unknown impact and attack vectors related to an insecure direez · ez publish | High7.5 | — | 2.0% | Oct 6, 2012 |
30Monitor | CVE-2010-2672No exploit | Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1ez · ez publish · CWE-89 | High7.5 | — | 1.3% | Jul 8, 2010 |
28Monitor | CVE-2003-0310Proof of concept | Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.ez · ez publish · CWE-79 | Medium6.8 | — | 3.2% | Jun 16, 2003 |
27Monitor | CVE-2012-4053No exploit | Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the autez · ez publish · CWE-352 | Medium6.8 | — | 0.6% | Jul 25, 2012 |
24Monitor | CVE-2019-12139No exploit | An XSS issue was discovered in the Admin UI in eZ Platform 2.x.ez · ezplatform-admin-ui · CWE-79 | Medium6.1 | — | 0.8% | May 16, 2019 |
24Monitor | CVE-2017-1000431No exploit | eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk ez · ez publish · CWE-79 | Medium6.1 | — | 0.7% | Jan 2, 2018 |
21Monitor | CVE-2007-4494No exploit | The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote attaez · ez publish | Medium5.0 | — | 1.7% | Aug 22, 2007 |
20Monitor | CVE-2005-4852No exploit | The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI toez · ez publish · CWE-264 | Medium5.0 | — | 1.1% | Dec 31, 2005 |
20Monitor | CVE-2005-4854No exploit | eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authenticez · ez publish · CWE-264 | Medium5.0 | — | 1.1% | Dec 31, 2005 |
20Monitor | CVE-2005-4856No exploit | The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle autez · ez publish · CWE-19 | Medium5.0 | — | 1.1% | Dec 31, 2005 |
20Monitor | CVE-2005-4850No exploit | eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers ez · ez publish · CWE-264 | Medium5.0 | — | 1.0% | Dec 31, 2005 |
17Monitor | CVE-2006-0938No exploit | Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via ez · ez publish · CWE-79 | Medium4.3 | — | 1.3% | Feb 28, 2006 |
17Monitor | CVE-2010-2671No exploit | Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitraryez · ez publish · CWE-79 | Medium4.3 | — | 1.3% | Jul 8, 2010 |
16Monitor | CVE-2006-7219No exploit | eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users toez · ez publish · CWE-264 | Medium4.0 | — | 1.0% | Jul 6, 2007 |
16Monitor | CVE-2006-7218No exploit | eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allowez · ez publish · CWE-264 | Medium4.0 | — | 1.0% | Jul 6, 2007 |
16Monitor | CVE-2005-4857No exploit | eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denialez · ez publish · CWE-399 | Medium4.0 | — | 0.9% | Dec 31, 2005 |
16Monitor | CVE-2005-4851No exploit | eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypasez · ez publish · CWE-287 | Medium4.0 | — | 0.9% | Dec 31, 2005 |
14Monitor | CVE-2005-4855No exploit | Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does nez · ez publish · CWE-264 | Low3.5 | — | 0.7% | Dec 31, 2005 |
11Monitor | CVE-2012-1597Proof of concept | Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5 aez · ezjscore · CWE-79 | Low2.6 | — | 4.1% | Aug 16, 2012 |
- CVE-2007-449341Plan
eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has un
CriticalCVSS 10.0No exploitEPSS 2%ez · ez publishAug 22, 2007
- CVE-2020-1080640Plan
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.
CriticalCVSS 9.8No exploitEPSS 2%ez · ez publish-kernelMar 22, 2020
- CVE-2005-485337Monitor
The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 2005081
CriticalCVSS 9.4No exploitEPSS 1%ez · ez publishDec 31, 2005
- CVE-2008-684431Monitor
The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows
HighCVSS 7.5Proof of conceptEPSS 3%ez · ez publishJul 2, 2009
- CVE-2012-156531Monitor
Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 has unknown impact and attack vectors related to an insecure dire
HighCVSS 7.5No exploitEPSS 2%ez · ez publishOct 6, 2012
- CVE-2010-267230Monitor
Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1
HighCVSS 7.5No exploitEPSS 1%ez · ez publishJul 8, 2010
- CVE-2003-031028Monitor
Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.
MediumCVSS 6.8Proof of conceptEPSS 3%ez · ez publishJun 16, 2003
- CVE-2012-405327Monitor
Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the aut
MediumCVSS 6.8No exploitEPSS 1%ez · ez publishJul 25, 2012
- CVE-2019-1213924Monitor
An XSS issue was discovered in the Admin UI in eZ Platform 2.x.
MediumCVSS 6.1No exploitEPSS 1%ez · ezplatform-admin-uiMay 16, 2019
- CVE-2017-100043124Monitor
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk
MediumCVSS 6.1No exploitEPSS 1%ez · ez publishJan 2, 2018
- CVE-2007-449421Monitor
The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote atta
MediumCVSS 5.0No exploitEPSS 2%ez · ez publishAug 22, 2007
- CVE-2005-485220Monitor
The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI to
MediumCVSS 5.0No exploitEPSS 1%ez · ez publishDec 31, 2005
- CVE-2005-485420Monitor
eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authentic
MediumCVSS 5.0No exploitEPSS 1%ez · ez publishDec 31, 2005
- CVE-2005-485620Monitor
The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle aut
MediumCVSS 5.0No exploitEPSS 1%ez · ez publishDec 31, 2005
- CVE-2005-485020Monitor
eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers
MediumCVSS 5.0No exploitEPSS 1%ez · ez publishDec 31, 2005
- CVE-2006-093817Monitor
Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3No exploitEPSS 1%ez · ez publishFeb 28, 2006
- CVE-2010-267117Monitor
Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitrary
MediumCVSS 4.3No exploitEPSS 1%ez · ez publishJul 8, 2010
- CVE-2006-721916Monitor
eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users to
MediumCVSS 4.0No exploitEPSS 1%ez · ez publishJul 6, 2007
- CVE-2006-721816Monitor
eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allow
MediumCVSS 4.0No exploitEPSS 1%ez · ez publishJul 6, 2007
- CVE-2005-485716Monitor
eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial
MediumCVSS 4.0No exploitEPSS 1%ez · ez publishDec 31, 2005
- CVE-2005-485116Monitor
eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypas
MediumCVSS 4.0No exploitEPSS 1%ez · ez publishDec 31, 2005
- CVE-2005-485514Monitor
Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does n
LowCVSS 3.5No exploitEPSS 1%ez · ez publishDec 31, 2005
- CVE-2012-159711Monitor
Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5 a
LowCVSS 2.6Proof of conceptEPSS 4%ez · ezjscoreAug 16, 2012