Ektron's vulnerability profile centers on its content-management-system product line, a modestly represented but more prominent than typical vendor in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability; the recurring exposure spans web-layer input-handling and output-encoding weaknesses—cross-site scripting, SQL injection, CSRF, and downstream injection flaws—that are characteristic of CMS platforms lacking robust input sanitization and context-aware output encoding. Defenders should treat Ektron CMS instances as a patching priority and restrict administrative access; live severity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ektron over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5357CRITICAL Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code wi | Oct 30, 2017 | 9.8 | 83 | NO | YES |
CVE-2012-5358CRITICAL The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with enableDocumentFunction set to true, which allows remote attacke | Oct 30, 2017 | 9.8 | 32 | NO | NO |
CVE-2015-0923MEDIUM The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1 allows remote attackers to read ar | Feb 14, 2015 | 5.0 | 32 | NO | YES |
CVE-2008-3499HIGH Unspecified vulnerability in "a page in the workarea folder" in Ektron CMS400.NET 7.00 through 7.04 and 7.50 through 7.52 has unknown impact and attack vectors. | Aug 6, 2008 | 10.0 | 27 | NO | NO |
CVE-2015-3624MEDIUM Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.1 | Jun 9, 2015 | 5.8 | 24 | NO | YES |
CVE-2015-0931MEDIUM Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to execute arbitrary code via a cra | Feb 14, 2015 | 6.8 | 23 | NO | NO |
CVE-2016-6201MEDIUM Cross-site scripting (XSS) vulnerability in Ektron Content Management System (CMS) before 9.1.0.184 SP3 (9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or | Jul 3, 2017 | 6.1 | 21 | NO | NO |
CVE-2008-5122HIGH SQL injection vulnerability in WorkArea/ContentRatingGraph.aspx in Ektron CMS400.NET 7.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the res paramet | Nov 18, 2008 | 7.5 | 19 | NO | NO |
CVE-2016-6133MEDIUM Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or HTML via | Jul 25, 2017 | 6.1 | 17 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.114) allow remote au | Jun 9, 2015 | 3.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ektron.
Media articles that mention a CVE ID that affects a product developed by Ektron — matched by CVE ID, not by vendor name.