Content Navigator
Vendor:
First CVE: Dec 19, 2013 · Active for 12 years
40
Total CVEs
More Total CVEs than 98% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Content Navigator over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2013
12 years ago
Most Recent CVE
Apr 2, 2026
116 days ago
CVE Severity & Scoring
Content Navigator40 CVEs
10%
78%
13%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (2.5%)
Network34 (85.0%)
Unknown5 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (87.5%)
High0 (0.0%)
Unknown5 (12.5%)
User Interaction
None15 (37.5%)
Unknown5 (12.5%)
Required20 (50.0%)
Privileges Required
Low27 (67.5%)
High1 (2.5%)
None7 (17.5%)
Unknown5 (12.5%)
Top CVEs
Signals from CVEs in this product scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-4034HIGH IBM Content Navigator 3.0CD is could allow an attacker to execute arbitrary code on a user's workstation. When editing an executable file in ICN with Edit service, it will be execu | Mar 14, 2019 | 8.8 | 29 | NO | NO |
CVE-2022-43581HIGH IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an aut | Dec 7, 2022 | 8.8 | 28 | NO | NO |
CVE-2020-4253HIGH IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 175559. | Mar 24, 2020 | 8.8 | 25 | NO | NO |
CVE-2018-1364HIGH IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expo | Jan 29, 2018 | 8.2 | 25 | NO | NO |
CVE-2018-1366HIGH IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadshe | Feb 7, 2018 | 7.8 | 24 | NO | NO |
CVE-2026-1243MEDIUM IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web | Apr 2, 2026 | 5.4 | 21 | NO | NO |
CVE-2020-4757MEDIUM IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the | Dec 21, 2020 | 6.4 | 21 | NO | NO |
CVE-2019-4092MEDIUM IBM Content Navigator 2.0.3 and 3.0CD could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted | Apr 25, 2019 | 6.1 | 21 | NO | NO |
CVE-2023-40684MEDIUM IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript | Oct 4, 2023 | 5.4 | 20 | NO | NO |
CVE-2021-29714MEDIUM IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968. | Aug 9, 2021 | 6.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (40 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (40 CVEs).
Media Mentions
Signals from CVEs in this product scope (40 CVEs).
Top CNAs Publishing CVEs For Content Navigator
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2.0 | 2 | 5.3 | 0.3% | 0 | 0 |
| 3.1.0 | 4 | 5.5 | 0.2% | 0 | 0 |
| 3.0.8 | 2 | 3.5 | 0.9% | 0 | 0 |
| 3.0.7 | 2 | 3.5 | 0.9% | 0 | 0 |
| 3.0.3 | 3 | 7.1 | 1.4% | 0 | 0 |
| 3.0.2 | 3 | 7.1 | 1.4% | 0 | 0 |
| 3.0.15 | 4 | 5.5 | 0.2% | 0 | 0 |
| 3.0.14 | 1 | 5.4 | 0.4% | 0 | 0 |
| 3.0.13 | 2 | 5.4 | 0.3% | 0 | 0 |
| 3.0.11 | 4 | 5.5 | 0.3% | 0 | 0 |
| 3.0.1 | 4 | 6.0 | 0.7% | 0 | 0 |
| 3.0.0 | 27 | 5.6 | 0.9% | 0 | 0 |
| 2.0.3.8 | 3 | 5.4 | 0.6% | 0 | 0 |
| 2.0.3.7 | 2 | 5.4 | 0.6% | 0 | 0 |
| 2.0.3.6 | 2 | 5.4 | 0.6% | 0 | 0 |
| 2.0.3.5 | 2 | 5.4 | 0.6% | 0 | 0 |
| 2.0.3 | 7 | 5.4 | 1.0% | 0 | 0 |
| 2.0.2.8 | 1 | 7.8 | 0.9% | 0 | 0 |
| 2.0.2.7 | 1 | 7.8 | 0.9% | 0 | 0 |
| 2.0.2 | 4 | 3.7 | 1.2% | 0 | 0 |