Known vulnerabilities in ezpublish-legacy
Vendor:
eZ systems
Software:
ezpublish-legacy
Software CPE:
cpe:2.3:a:ez_systems:ezpublish-legacy:*:*:*:*:*:*:*:*
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
v2017.12.7.3
v2019.03.6
5.4.14
5.4.13
2017.12.7.4
2019.03.6.1
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.5.10
3.5.11
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
3.6.10
3.6.11
3.6.12
3.7.0
3.7.1
3.7.2
3.7.3
3.7.4
3.7.5
3.7.6
3.7.7
3.7.8
3.7.9
3.7.10
3.8.0
3.8.1
3.8.2
3.8.3
3.8.4
3.8.5
3.8.6
3.8.7
3.8.8
3.8.9
3.8.10
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
3.9.5
3.10.0
3.10.1
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.20
2019.03.6
2019.03.5.1
2019.03.5
2019.03.4.2
2019.03.4
2019.03.3
2019.03.2
2019.03.1
2019.03.0
2018.09.5
2018.09.4
2018.09.3
2018.09.2
2018.09.1.3
2018.09.1.2
2018.09.1.1
2018.09.1
2018.09.0
2018.06.1.4
2018.06.1.3
2018.06.1.2
2018.06.1.1
2018.06.1
2018.06.0
2017.12.7.3
2017.12.7.2
2017.12.7
2017.12.6
2017.12.5
2017.12.4.3
2017.12.4.2
2017.12.4.1
2017.12.4
2017.12.3.2
2017.12.3.1
2017.12.3
2017.12.2.2
2017.12.2.1
2017.12.2
2017.12.1.1
2017.12.1
2017.12.0
2017.10.1
2017.10.0
2017.08.1.1
2017.08.1
2017.08.0
2015.01.3
2015.01.2
2015.01.1
2015.01.0
2014.11.2
2014.11.1
2014.11.0
2014.07.2
2014.07.1
2014.07.0
2014.05.2
2014.05.1
2014.05.0
2014.03.2
2014.03.1
2014.01.2
2014.01.1
2014.01.0
2013.11.0
2013.11
2013.1
2013.09.0
2013.07.3
2013.07.1
2013.07.0
2013.06.0
2013.05.0
2013.05
2013.04.0
2012.12
2012.11
2012.9
2011.9
4.4.0
4.3.0
4.2.0
4.1.4
4.1.3
4.1.2
4.1.1
4.1.0
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU56353 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
CWE-89 | High | 5.4.14, 2017.12.7.4, 2019.03.6.1 | 06.09.2021 |
SB2021090617 |
||
| #VU47354 - Improper Control of Generation of Code ('Code Injection') |
CWE-94 | Medium | 2017.12.7.3, 2019.03.5.1 | 06.10.2020 |
SB2020100607 |