ExpressionEngine is a content management system with a concentrated vulnerability footprint centered on application-layer input-handling weaknesses spanning cross-site scripting, SQL injection, code injection, and improper input validation. The platform's disclosures reflect the parsing and user-input processing demands typical of web applications that accept and render dynamic content, and a meaningful share of vulnerabilities reach serious severity levels with a moderate tendency toward public exploit availability. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Expressionengine over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33199CRITICAL In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file names of icon.png and i | Aug 12, 2021 | 9.8 | 31 | NO | NO |
CVE-2023-22953HIGH In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user. | Feb 9, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-27230HIGH ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under t | Mar 15, 2021 | 8.8 | 26 | NO | NO |
CVE-2025-59473HIGH SQL Injection vulnerability in the Structure for Admin authenticated user | Jan 26, 2026 | 7.2 | 24 | NO | NO |
CVE-2020-13443HIGH ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft actions. A user with | Jun 24, 2020 | 8.8 | 23 | NO | NO |
CVE-2014-5387MEDIUM Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) | Nov 4, 2014 | 6.5 | 23 | NO | NO |
CVE-2018-17874MEDIUM ExpressionEngine before 4.3.5 has reflected XSS. | Oct 1, 2018 | 6.1 | 21 | NO | NO |
CVE-2009-1070MEDIUM Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web | Mar 26, 2009 | 4.3 | 21 | NO | YES |
CVE-2017-0897HIGH ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution. | Jun 22, 2017 | 7.5 | 20 | NO | NO |
CVE-2024-38454MEDIUM ExpressionEngine before 7.4.11 allows XSS. | Jun 16, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Expressionengine.
Media articles that mention a CVE ID that affects a product developed by Expressionengine — matched by CVE ID, not by vendor name.