Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-53864

17
FAUCET Score

CVE-2024-53864 describes an XSS vulnerability in the Ibexa Admin UI Bundle, specifically within the Content name pattern mechanism used to build content names. This medium-severity vulnerability (CVSS 5.3) requires content edit permissions for exploitation and could lead to limited impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, no known exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage. Users are advised to upgrade to version 4.6.14 to remediate this issue, as existing injected XSS will not execute after the fix.

Impacted Technologies

VendorProductVersion(s)CPE
IbexaAdmin-Ui
>= 4.6.0, < 4.6.14CNA affected

CVSS Data

CVSS version used by this source: 4.0

5.3MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.51%
Probability of exploitation in next 30 days
EPSS Percentile
40.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0051 is in the 43rd percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

composerpatch availablevia ghsa
Product: ibexa/admin-uiFixed in: 4.6.14

Vendor Advisories (1)

composerGHSA-8w3p-gf85-qcchmedium

Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern

Dec 2, 2024

References

developers.ibexa.co / security-advisories/ibexa-sa-2024-006-vulnerabilities-in-content-name-pattern-commerce-shop-and-varnish-vhost-templates
doc.ibexa.co / en/latest/update_and_migration/from_4.6/update_from_4.6
github.com / ibexa/admin-ui/commit/8ec824a8cf06c566ed88e4c21cc66f7ed42649fc
github.com / ibexa/admin-ui/security/advisories/GHSA-8w3p-gf85-qcch