Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ibexa

First CVE: Feb 18, 2022Active for: 4 yearsTotal CVEs: 10
16.5
VTI Score
Low

Ibexa develops digital experience and content management platforms, primarily centered on its EZ Platform kernel and commerce solutions, which serve as the foundation for web applications and enterprise content delivery. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes spanning cross-site scripting, authorization bypass, race conditions, and improper access control—patterns typical of large web application stacks where input validation, session management, and resource synchronization demand rigorous implementation. Defenders should prioritize Ibexa platform updates as part of broader application-layer patching cycles; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ibexa over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2022
4 years ago
Most Recent CVE
Mar 6, 2026
140 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-48367CRITICAL
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.
Mar 12, 20239.831NONO
CVE-2022-25337CRITICAL
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.
Feb 18, 20229.828NONO
CVE-2025-70363HIGH
Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object ID
Mar 6, 20267.527NONO
CVE-2022-48365HIGH
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.
Mar 12, 20237.224NONO
CVE-2021-46875MEDIUM
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1. An XSS attack can occur because JavaScript code can be uploaded in a .html or .js file.
Mar 12, 20236.122NONO
CVE-2021-46876MEDIUM
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existence.
Mar 12, 20235.320NONO
CVE-2022-41876MEDIUM
ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Informat
Nov 10, 20225.320NONO
CVE-2022-25336MEDIUM
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path a
Feb 18, 20225.319NONO
CVE-2020-23065MEDIUM
Cross Site Scripting vulnerabiltiy in eZ Systems AS eZPublish Platform v.5.4 and eZ Publish Legacy v.5.4 allows a remote authenticated attacker to execute arbitrary code via the vi
Jun 26, 20235.418NONO
CVE-2022-48366LOW
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack.
Mar 12, 20233.717NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
10%
50%
20%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low1 (10.0%)
High1 (10.0%)
None8 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ibexa.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ibexa — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ibexa's Products

View all 2 CNAs →

Top CWEs