xpressengine records
5 published records for vendor xpressengine.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-26642No exploit | XpressEngine file upload vulnerabilityxpressengine · xpressengine · CWE-434 | Critical9.8 | — | 1.2% | Jan 20, 2023 |
39Monitor | CVE-2011-10003No exploit | XpressEngine Update Query sql injectionxpressengine · xpressengine · CWE-89 | Critical9.8 | — | 0.6% | Feb 7, 2023 |
28Monitor | CVE-2009-4834Proof of concept | lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_conxpressengine · zeroboard · CWE-94 | Medium6.8 | — | 4.0% | May 4, 2010 |
21Monitor | CVE-2021-44911No exploit | XE before 1.11.6 is vulnerable to Unrestricted file upload via modules/menu/menu.admin.controller.php.xpressengine · xpressengine · CWE-79 | Medium5.4 | — | 0.6% | Feb 9, 2022 |
21Monitor | CVE-2021-44912No exploit | In XE 1.116, when uploading the Normal button, there is no restriction on the file suffix, which leads to any file uploading to the files dixpressengine · xpressengine · CWE-79 | Medium5.4 | — | 0.5% | Feb 9, 2022 |
- CVE-2021-2664239Monitor
XpressEngine file upload vulnerability
CriticalCVSS 9.8No exploitEPSS 1%xpressengine · xpressengineJan 20, 2023
- CVE-2011-1000339Monitor
XpressEngine Update Query sql injection
CriticalCVSS 9.8No exploitEPSS 1%xpressengine · xpressengineFeb 7, 2023
- CVE-2009-483428Monitor
lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_con
MediumCVSS 6.8Proof of conceptEPSS 4%xpressengine · zeroboardMay 4, 2010
- CVE-2021-4491121Monitor
XE before 1.11.6 is vulnerable to Unrestricted file upload via modules/menu/menu.admin.controller.php.
MediumCVSS 5.4No exploitEPSS 1%xpressengine · xpressengineFeb 9, 2022
- CVE-2021-4491221Monitor
In XE 1.116, when uploading the Normal button, there is no restriction on the file suffix, which leads to any file uploading to the files di
MediumCVSS 5.4No exploitEPSS 0%xpressengine · xpressengineFeb 9, 2022