E Vision maintains a niche content-management system whose vulnerability footprint, while modest in volume, reflects the complexity of web-facing publishing platforms handling user input and access control. The recurring exposure centers on this single product and its role as a backend system in editorial workflows. Current CVE volume, exploitation activity, and severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by E Vision over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0856HIGH Multiple SQL injection vulnerabilities in e-Vision CMS 2.02 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) iframe.php and (2) print.php. NOTE | Feb 21, 2008 | 7.5 | 32 | NO | YES |
CVE-2007-3251HIGH Multiple directory traversal vulnerabilities in e-Vision CMS 2.02 and earlier allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the admi | Jun 18, 2007 | 7.8 | 30 | NO | YES |
CVE-2007-3214MEDIUM SQL injection vulnerability in style.php in e-Vision CMS 2.02 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the temp | Jun 14, 2007 | 6.8 | 29 | NO | YES |
CVE-2006-5017HIGH SQL injection vulnerability in admin/all_users.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to execute arbitrary SQL commands via the from | Sep 27, 2006 | 7.5 | 28 | NO | YES |
CVE-2008-6551MEDIUM Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local fil | Mar 30, 2009 | 5.1 | 23 | NO | YES |
CVE-2006-5016MEDIUM Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to upload arbitrary files to the /ima | Sep 27, 2006 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by E Vision.
Media articles that mention a CVE ID that affects a product developed by E Vision — matched by CVE ID, not by vendor name.