Expressionengine
expressionengine
14 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (14)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SQL Injection vulnerability in the Structure for Admin authenticated user |
1Expressionengine 1Expressionengine Mar 17, 2025 Jun 16, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 ExpressionEngine before 7.4.11 allows XSS. |
In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user. |
1Expressionengine 1Expressionengine Nov 21, 2024 Feb 18, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to execute the attack. |
1Expressionengine 1Expressionengine Nov 21, 2024 Aug 12, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file names of icon.png and icon.svg. |
1Expressionengine 1Expressionengine Nov 21, 2024 Mar 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/language directory. |
1Expressionengine 1Expressionengine Nov 21, 2024 Jun 24, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft actions. A user with low privileges (member) is able to uplo...Show more |
1Expressionengine 1Expressionengine Nov 21, 2024 Oct 1, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ExpressionEngine before 4.3.5 has reflected XSS. |
1Expressionengine 1Expressionengine May 13, 2026 Nov 17, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection |
1Expressionengine 1Expressionengine May 13, 2026 Jun 22, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution. |
2Ellislab Expressionengine2Expressionengine ExpressionengineMay 6, 2026 Nov 4, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) category[] parameter to system/index.ph...Show more |
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter...Show more |
CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter. |
Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameter. |