ezsystems/ezpublish-legacy vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-38739Highezsystems/ezpublish-legacy: ezsystems/ezpublish-legacy has a SQL injection in dfscleanupGHSA-39J2-4P9J-5W4JMediumezsystems/ezpublish-legacy: Ez Platform Object Injection in legacy shop moduleGHSA-9895-26WR-4FGVHighezsystems/ezpublish-legacy: EZsystems Remote code execution in file uploadsGHSA-PQJM-XCP8-WGMMMediumezsystems/ezpublish-legacy: Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploadsGHSA-P9MP-VQ4V-V5M5Highezsystems/ezpublish-legacy: eZ Publish Legacy Passwordless login for LDAP usersGHSA-2VH3-CJ9J-MCJ5Mediumezsystems/ezpublish-legacy: eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error templateGHSA-82RV-45PC-V28WHighezsystems/ezpublish-legacy: eZ Publish Legacy Patch EZSA-2018-001 for Several vulnerabilitiesGHSA-CC2J-92JQ-WGJGHighezsystems/ezpublish-legacy: eZ Publish Information disclosure in backend content tree menuCVE-2020-10806Criticalezsystems/ezpublish-kernel: eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous TypeCVE-2017-1000431Mediumezsystems/ezpublish-legacy: eZ Publish Cross-site Scripting (XSS) vulnerabilityGHSA-JPWX-FFJQ-WR4WHighezsystems/ezpublish-legacy: Content object state fetch functions open to SQL injection

Stop the waste.
Protect your environment with Kodem.