Xpressengine

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2011-10003

    XpressEngine Update Query sql injection

    Last Modified: Mar 25, 2025
    Published: Feb 07, 2023

    CVE-2021-26642

    XpressEngine file upload vulnerability

    Last Modified: Apr 03, 2025
    Published: Jan 20, 2023

    CVE-2021-44912

    In XE 1.116, when uploading the Normal button, there is no restriction on the file suffix, which leads to any file uploading to the files directory. Since .htaccess only restricts the PHP type, uploading HTML-type files leads to stored XSS vulnerabilities. If the .htaccess configuration is improper, for example before the XE 1.11.2 version, you can upload the PHP type file to GETSHELL.

    Last Modified: Nov 21, 2024
    Published: Feb 09, 2022

    CVE-2021-44911

    XE before 1.11.6 is vulnerable to Unrestricted file upload via modules/menu/menu.admin.controller.php. When uploading the Mouse over button and When selected button, there is no restriction on the file suffix, which leads to any file uploading to the files directory. Since .htaccess only restricts the PHP type, uploading HTML-type files leads to stored XSS vulnerabilities.

    Last Modified: Nov 21, 2024
    Published: Feb 09, 2022

    CVE-2009-4834

    lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_connect.php.

    Last Modified: Apr 11, 2025
    Published: May 04, 2010
    Items Per Page
    Xpressengine Vulnerabilities & Security CVEs | CVE-DB