Episerver maintains a modestly represented content-management and digital-experience platform portfolio, with vulnerabilities concentrated in its core CMS products and recurring across web-application input-handling and access-control classes such as cross-site scripting, privilege-management flaws, XML external entity injection, and open redirects. The vendor's disclosures skew toward serious severity outcomes and frequently acquire public exploit code, reflecting the internet-facing nature and authentication-critical role of these platforms. Defenders should prioritize patches for exposed Episerver and Ektron CMS instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Episerver over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12596CRITICAL Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the "activateuser.aspx" page, | Oct 10, 2018 | 9.8 | 54 | NO | YES |
CVE-2017-17762HIGH XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc | Aug 29, 2018 | 7.5 | 37 | NO | YES |
CVE-2020-24550MEDIUM An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a | Mar 31, 2021 | 6.1 | 32 | NO | YES |
CVE-2012-1031MEDIUM Unspecified vulnerability in EPiServer CMS 5 and 6 through 6R2, in certain configurations using Forms Authentication, allows remote authenticated users to obtain WebAdmins access b | Feb 8, 2012 | 6.0 | 20 | NO | NO |
CVE-2012-1032MEDIUM Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker module 3.x before 3.4.5 for EPiServer allows remote attackers to inject arbitrary web script or HTML via unspeci | Sep 17, 2014 | 4.3 | 17 | NO | NO |
CVE-2012-1034MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the admin interface in EPiServer CMS through 6R2 allow remote attackers to inject arbitrary web script or HTML via unspecifie | Feb 8, 2012 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Episerver.
Media articles that mention a CVE ID that affects a product developed by Episerver — matched by CVE ID, not by vendor name.