High severity8.8NVD Advisory· Published Feb 9, 2023· Updated Jun 17, 2026
CVE-2023-22953
CVE-2023-22953
Description
In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:expressionengine:expressionengine:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:expressionengine:expressionengine:*:*:*:*:*:*:*:*range: <7.2.6
- (no CPE)
- (no CPE)range: <7.2.6
Patches
Vulnerability mechanics
References
3- docs.expressionengine.com/latest/installation/changelog.htmlnvdRelease Notes
- hackerone.com/reports/1820492nvdPermissions Required
- gist.github.com/ahmedsherif/7b8f18a54a80ae0ac5ff6307c35b7d43nvd
News mentions
0No linked articles in our index yet.