Search Results (23 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2017-1000431 1 Ez 1 Ez Publish 2024-11-21 N/A
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.
CVE-2012-4053 1 Ez 1 Ez Publish 2024-08-06 N/A
Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVE-2012-1597 1 Ez 1 Ezjscore 2024-08-06 N/A
Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.