Ezsystems/ezpublish-legacy
10 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Ezsystems/ezpublish-legacy, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Ezsystems/ezpublish-legacy CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- Medium1
Latest CVEs
The 10 most recently published vulnerabilities affecting Ezsystems/ezpublish-legacy.
- GHSA-39j2-4p9j-5w4jEz Platform Object Injection in legacy shop module—
- GHSA-9895-26wr-4fgvEZsystems Remote code execution in file uploads—
- GHSA-pqjm-xcp8-wgmmEz Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads—
- GHSA-p9mp-vq4v-v5m5eZ Publish Legacy Passwordless login for LDAP users—
- GHSA-2vh3-cj9j-mcj5eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template—
- GHSA-82rv-45pc-v28weZ Publish Legacy Patch EZSA-2018-001 for Several vulnerabilities—
- GHSA-cc2j-92jq-wgjgeZ Publish Information disclosure in backend content tree menu—
- GHSA-jpwx-ffjq-wr4wContent object state fetch functions open to SQL injection—
- CVE-2020-10806eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to ...9.8
- CVE-2017-1000431eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authe...6.1
Product grouping is registry-driven, with AI assist and human review. How it works