CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2025-59473 HIGH

SQL Injection vulnerability in the Structure for Admin authenticated user

CVSS 7.2 EPSS 0.30% Jan 26, 2026
CVE-2024-38454 MEDIUM

ExpressionEngine before 7.4.11 allows XSS.

CVSS 6.1 EPSS 0.30% Jun 16, 2024
CVE-2021-44534 MEDIUM

Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.

CVSS 6.5 EPSS 0.56% May 31, 2024
CVE-2023-22953 HIGH

In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user.

CVSS 8.8 EPSS 1.43% Feb 9, 2023
CVE-2020-8242 HIGH

Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel…

CVSS 7.2 EPSS 0.93% Feb 18, 2022
CVE-2021-33199 CRITICAL

In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file na…

CVSS 9.8 EPSS 1.36% Aug 12, 2021
CVE-2021-27230 HIGH

ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _…

CVSS 8.8 EPSS 2.83% Mar 15, 2021
CVE-2020-13443 HIGH

ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft…

CVSS 8.8 EPSS 4.13% Jun 24, 2020
CVE-2018-17874 MEDIUM

ExpressionEngine before 4.3.5 has reflected XSS.

CVSS 6.1 EPSS 0.65% Oct 1, 2018
CVE-2017-1000160 MEDIUM

EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection

CVSS 5.4 EPSS 0.51% Nov 17, 2017
CVE-2017-0897 HIGH

ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to rem…

CVSS 7.5 EPSS 4.04% Jun 22, 2017
CVE-2014-5387 MEDIUM

Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1)…

CVSS 6.5 EPSS 1.65% Nov 4, 2014
CVE-2009-1070 MEDIUM

Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to…

CVSS 4.3 EPSS 1.72% Mar 24, 2009
CVE-2008-0202 MEDIUM

CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP respo…

CVSS 4.3 EPSS 1.24% Jan 10, 2008
CVE-2008-0201 MEDIUM

Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 EPSS 1.31% Jan 10, 2008

Showing 1 to 15 CVEs · page 1