Skip to content
Noroxi

xpressengine records

5 published records for vendor xpressengine.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
40%
Median publish → KEV
No record has entered KEV

All records

5 records
  • XpressEngine file upload vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    xpressengine · xpressengineJan 20, 2023

  • XpressEngine Update Query sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    xpressengine · xpressengineFeb 7, 2023

  • CVE-2009-4834
    28Monitor

    lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_con

    MediumCVSS 6.8Proof of conceptEPSS 4%

    xpressengine · zeroboardMay 4, 2010

  • XE before 1.11.6 is vulnerable to Unrestricted file upload via modules/menu/menu.admin.controller.php.

    MediumCVSS 5.4No exploitEPSS 1%

    xpressengine · xpressengineFeb 9, 2022

  • In XE 1.116, when uploading the Normal button, there is no restriction on the file suffix, which leads to any file uploading to the files di

    MediumCVSS 5.4No exploitEPSS 0%

    xpressengine · xpressengineFeb 9, 2022