VYPR

Expressionengine

by Expressionengine

Source repositories

CVEs (7)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-1000160Med0.355.40.00Nov 17, 2017EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection
CVE-2006-04610.040.09Jan 27, 2006Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer).
CVE-2009-10700.030.03Mar 26, 2009Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter.
CVE-2025-594730.000.00Jan 26, 2026SQL Injection vulnerability in the Structure for Admin authenticated user
CVE-2014-53870.000.00Nov 4, 2014Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) category[] parameter to system/index.php or the (3) tbl_sort[0][] parameter in the comment module to system/index.php.
CVE-2008-02010.000.01Jan 10, 2008Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameter.
CVE-2008-02020.000.01Jan 10, 2008CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter.