Ez maintains a focused vulnerability footprint concentrated in its eZ Publish content management system and related kernel components, which serve as the core platform for web content delivery across a range of deployments. While the vendor's disclosure volume is modest and does not skew toward critical severity, its vulnerabilities frequently acquire public exploit code, underscoring the appeal of CMS-targeting attack chains. The recurring weakness classes—cross-site scripting, cross-site request forgery, SQL injection, and improper authentication—are characteristic of web application input handling and session management, reflecting the inherent complexity of content management platforms that process and serve user-contributed or templated content. Defenders should prioritize patching these product lines in internet-facing deployments and maintain inventory of legacy instances, which often remain at risk longer than supported versions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ez over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10806CRITICAL eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow rem | Mar 22, 2020 | 9.8 | 31 | NO | NO |
CVE-2008-6844HIGH The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows remote attackers to gain privileges as o | Jul 2, 2009 | 7.5 | 29 | NO | YES |
CVE-2007-4493HIGH eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unknown impact and attack vectors, as demo | Aug 23, 2007 | 10.0 | 27 | NO | NO |
CVE-2003-0310MEDIUM Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script. | Jun 16, 2003 | 6.8 | 27 | NO | YES |
CVE-2012-1565HIGH Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 has unknown impact and attack vectors related to an insecure direct object reference. | Oct 6, 2012 | 7.5 | 24 | NO | NO |
CVE-2005-4853HIGH The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does not restrict edit permissions to | Dec 31, 2005 | 9.4 | 23 | NO | NO |
CVE-2017-1000431MEDIUM eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may | Jan 2, 2018 | 6.1 | 22 | NO | NO |
Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5 allows remote attackers to inject arbitra | Aug 17, 2012 | 2.6 | 22 | NO | YES |
CVE-2010-2672HIGH Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) SectionID and (2) SearchTimestamp para | Jul 8, 2010 | 7.5 | 22 | NO | NO |
CVE-2019-12139MEDIUM An XSS issue was discovered in the Admin UI in eZ Platform 2.x. This affects ezplatform-admin-ui 1.3.x before 1.3.5 and 1.4.x before 1.4.4, and ezplatform-page-builder 1.1.x before | May 16, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ez.
Media articles that mention a CVE ID that affects a product developed by Ez — matched by CVE ID, not by vendor name.