Vulnerabilities
10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-59473 | SQL Injection vulnerability in the Structure for Admin authenticated user SQL Injection vulnerability in the Structure for Admin authenticated user NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2024-38454 | ExpressionEngine before 7.4.11 allows XSS. ExpressionEngine before 7.4.11 allows XSS. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-22953 | In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user. In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2020-8242 | Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to execute the attack. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2021-33199 | In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file nam In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file names of icon.png and icon.svg. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2021-27230 | ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _l ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/language directory. NVD description · AI analysis pending | 8.8 | 3% | PoC ×2 |
| — | |
| CVE-2020-13443 | ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft actions. A user with low privileges (member) is able to upload this. It is possible to bypass the MIME type check and file-extension check while uploading new files. Short aliases are not used for an attachment; instead, direct access is allowed to the uploaded files. It is possible to upload PHP only if one has member access, or registration/forum is enabled and one can create a member with the default group id of 5. To exploit this, one must to be able to send and compose messages (at least). NVD description · AI analysis pending | 8.8 | 4% | PoC |
| — | |
| CVE-2018-17874 | ExpressionEngine before 4.3.5 has reflected XSS. ExpressionEngine before 4.3.5 has reflected XSS. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2017-1000160 | EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2017-0897 | ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution. NVD description · AI analysis pending | 7.5 | 4% |
| — |