ibexa kayıtları
ibexa üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %81,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-203 Observable Discrepancy1
- CWE-269 Improper Privilege Management1
- CWE-284 Improper Access Control1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-639 Authorization Bypass Through User-Controlled Key1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-25337İstismar yok | Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.ibexa · ez platform kernel · CWE-74 | Kritik9,8 | — | %1,1 | 18 Şub 2022 |
39İzleyin | CVE-2022-48367İstismar yok | An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28.ibexa · digital experience platform · CWE-862 | Kritik9,8 | — | %0,7 | 12 Mar 2023 |
30İzleyin | CVE-2025-70363İstismar yok | Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access ibexa · ez platform · CWE-284 | Yüksek7,5 | — | %0,2 | 6 Mar 2026 |
28İzleyin | CVE-2022-48365İstismar yok | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26.ibexa · digital experience platform · CWE-269 | Yüksek7,2 | — | %0,9 | 12 Mar 2023 |
28İzleyin | CVE-2024-43369İstismar yok | Persistent Cross-site Scripting in Ibexa RichText Field Typeibexa · fieldtype-richtext · CWE-79 | Yüksek7,2 | — | %0,4 | 15 Ağu 2024 |
24İzleyin | CVE-2021-46875İstismar yok | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1.ibexa · ez platform kernel · CWE-79 | Orta6,1 | — | %0,4 | 12 Mar 2023 |
21İzleyin | CVE-2022-41876Kavram kanıtı | ezplatform-graphql GraphQL queries can expose password hashesibexa · ezplatform-graphql · CWE-200 | Orta5,3 | — | %1,4 | 10 Kas 2022 |
21İzleyin | CVE-2022-25336İstismar yok | Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks agaiibexa · ez platform kernel · CWE-639 | Orta5,3 | — | %0,7 | 18 Şub 2022 |
21İzleyin | CVE-2021-46876İstismar yok | An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1.ibexa · ez platform kernel · CWE-203 | Orta5,3 | — | %0,5 | 12 Mar 2023 |
21İzleyin | CVE-2020-23065İstismar yok | Cross Site Scripting vulnerabiltiy in eZ Systems AS eZPublish Platform v.5.4 and eZ Publish Legacy v.5.4 allows a remote authenticated attacibexa · ezpublish legacy · CWE-79 | Orta5,4 | — | %0,5 | 26 Haz 2023 |
14İzleyin | CVE-2022-48366İstismar yok | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19.ibexa · commerce · CWE-362 | Düşük3,7 | — | %0,5 | 12 Mar 2023 |
- CVE-2022-2533739İzleyin
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.
KritikCVSS 9,8İstismar yokEPSS %1ibexa · ez platform kernel18 Şub 2022
- CVE-2022-4836739İzleyin
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28.
KritikCVSS 9,8İstismar yokEPSS %1ibexa · digital experience platform12 Mar 2023
- CVE-2025-7036330İzleyin
Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access
YüksekCVSS 7,5İstismar yokEPSS %0ibexa · ez platform6 Mar 2026
- CVE-2022-4836528İzleyin
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26.
YüksekCVSS 7,2İstismar yokEPSS %1ibexa · digital experience platform12 Mar 2023
- CVE-2024-4336928İzleyin
Persistent Cross-site Scripting in Ibexa RichText Field Type
YüksekCVSS 7,2İstismar yokEPSS %0ibexa · fieldtype-richtext15 Ağu 2024
- CVE-2021-4687524İzleyin
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1.
OrtaCVSS 6,1İstismar yokEPSS %0ibexa · ez platform kernel12 Mar 2023
- CVE-2022-4187621İzleyin
ezplatform-graphql GraphQL queries can expose password hashes
OrtaCVSS 5,3Kavram kanıtıEPSS %1ibexa · ezplatform-graphql10 Kas 2022
- CVE-2022-2533621İzleyin
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks agai
OrtaCVSS 5,3İstismar yokEPSS %1ibexa · ez platform kernel18 Şub 2022
- CVE-2021-4687621İzleyin
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1.
OrtaCVSS 5,3İstismar yokEPSS %1ibexa · ez platform kernel12 Mar 2023
- CVE-2020-2306521İzleyin
Cross Site Scripting vulnerabiltiy in eZ Systems AS eZPublish Platform v.5.4 and eZ Publish Legacy v.5.4 allows a remote authenticated attac
OrtaCVSS 5,4İstismar yokEPSS %0ibexa · ezpublish legacy26 Haz 2023
- CVE-2022-4836614İzleyin
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19.
DüşükCVSS 3,7İstismar yokEPSS %0ibexa · commerce12 Mar 2023