Expressionengine

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 14
    Known Exploited: 0
    1
    Critical Level Threats
    6
    High Level Threats
    7
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-59473

    SQL Injection vulnerability in the Structure for Admin authenticated user

    Last Modified: Feb 13, 2026
    Published: Jan 26, 2026

    CVE-2024-38454

    ExpressionEngine before 7.4.11 allows XSS.

    Last Modified: Mar 17, 2025
    Published: Jun 16, 2024

    CVE-2023-22953

    In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user.

    Last Modified: Nov 21, 2024
    Published: Feb 09, 2023

    CVE-2020-8242

    Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to execute the attack.

    Last Modified: Nov 21, 2024
    Published: Feb 18, 2022

    CVE-2021-33199

    In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file names of icon.png and icon.svg.

    Last Modified: Nov 21, 2024
    Published: Aug 12, 2021
    Items Per Page
    Expressionengine Vulnerabilities & Security CVEs | CVE-DB