Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ektron

First CVE: Aug 6, 2008Active for: 18 yearsTotal CVEs: 12
39.8
VTI Score
Medium

Ektron's vulnerability profile centers on its content-management-system product line, a modestly represented but more prominent than typical vendor in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability; the recurring exposure spans web-layer input-handling and output-encoding weaknesses—cross-site scripting, SQL injection, CSRF, and downstream injection flaws—that are characteristic of CMS platforms lacking robust input sanitization and context-aware output encoding. Defenders should treat Ektron CMS instances as a patching priority and restrict administrative access; live severity and current exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ektron over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2008
17 years ago
Most Recent CVE
Oct 30, 2017
3,189 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-5357CRITICAL
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code wi
Oct 30, 20179.883NOYES
CVE-2012-5358CRITICAL
The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with enableDocumentFunction set to true, which allows remote attacke
Oct 30, 20179.832NONO
CVE-2015-0923MEDIUM
The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1 allows remote attackers to read ar
Feb 14, 20155.032NOYES
CVE-2008-3499HIGH
Unspecified vulnerability in "a page in the workarea folder" in Ektron CMS400.NET 7.00 through 7.04 and 7.50 through 7.52 has unknown impact and attack vectors.
Aug 6, 200810.027NONO
CVE-2015-3624MEDIUM
Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.1
Jun 9, 20155.824NOYES
CVE-2015-0931MEDIUM
Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to execute arbitrary code via a cra
Feb 14, 20156.823NONO
CVE-2016-6201MEDIUM
Cross-site scripting (XSS) vulnerability in Ektron Content Management System (CMS) before 9.1.0.184 SP3 (9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or
Jul 3, 20176.121NONO
CVE-2008-5122HIGH
SQL injection vulnerability in WorkArea/ContentRatingGraph.aspx in Ektron CMS400.NET 7.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the res paramet
Nov 18, 20087.519NONO
CVE-2016-6133MEDIUM
Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or HTML via
Jul 25, 20176.117NONO
CVE-2015-4427LOW
Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.114) allow remote au
Jun 9, 20153.516NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
17%
50%
17%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (33.3%)
Unknown8 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (33.3%)
High0 (0.0%)
Unknown8 (66.7%)
User Interaction
None2 (16.7%)
Unknown8 (66.7%)
Required2 (16.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (33.3%)
Unknown8 (66.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
16.7% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ektron.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ektron — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ektron's Products

View all 2 CNAs →

Top CWEs