Skip to main content

Vendor archive

ibexa CVEs

Beta · best-effort

10 CVEs tagged to vendor ibexa2 Critical, 3 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2025-70363

Published Mar 6, 2026

Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object I…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-46876

Published Mar 12, 2023

An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existence.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46875

Published Mar 12, 2023

An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1. An XSS attack can occur because JavaScript code can be uploaded in a .html or .js file.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41876

Published Nov 10, 2022

ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Informa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25337

Published Feb 18, 2022

Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-25336

Published Feb 18, 2022

Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1