Ibexa develops digital experience and content management platforms, primarily centered on its EZ Platform kernel and commerce solutions, which serve as the foundation for web applications and enterprise content delivery. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes spanning cross-site scripting, authorization bypass, race conditions, and improper access control—patterns typical of large web application stacks where input validation, session management, and resource synchronization demand rigorous implementation. Defenders should prioritize Ibexa platform updates as part of broader application-layer patching cycles; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ibexa over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-48367CRITICAL An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled. | Mar 12, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-25337CRITICAL Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames. | Feb 18, 2022 | 9.8 | 28 | NO | NO |
CVE-2025-70363HIGH Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object ID | Mar 6, 2026 | 7.5 | 27 | NO | NO |
CVE-2022-48365HIGH An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges. | Mar 12, 2023 | 7.2 | 24 | NO | NO |
CVE-2021-46875MEDIUM An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1. An XSS attack can occur because JavaScript code can be uploaded in a .html or .js file. | Mar 12, 2023 | 6.1 | 22 | NO | NO |
CVE-2021-46876MEDIUM An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existence. | Mar 12, 2023 | 5.3 | 20 | NO | NO |
CVE-2022-41876MEDIUM ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Informat | Nov 10, 2022 | 5.3 | 20 | NO | NO |
CVE-2022-25336MEDIUM Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path a | Feb 18, 2022 | 5.3 | 19 | NO | NO |
CVE-2020-23065MEDIUM Cross Site Scripting vulnerabiltiy in eZ Systems AS eZPublish Platform v.5.4 and eZ Publish Legacy v.5.4 allows a remote authenticated attacker to execute arbitrary code via the vi | Jun 26, 2023 | 5.4 | 18 | NO | NO |
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack. | Mar 12, 2023 | 3.7 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ibexa.
Media articles that mention a CVE ID that affects a product developed by Ibexa — matched by CVE ID, not by vendor name.