eZ Publish API and kernel. This is the heart of eZ Publish 5.
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2022-48367 ezsystems/ezpublish-kernel is vulnerable to Missing Authorization in versions 7.5.0 - 7.5.28. | 7.5.0 - 7.5.28 | Critical |
CVE-2022-48365 ezsystems/ezpublish-kernel is vulnerable to Improper Privilege Management in versions 7.5.0 - 7.5.30. | 7.5.0 - 7.5.30 | High |
CVE-2020-10806 ezsystems/ezpublish-kernel is vulnerable to Security Vulnerability in versions 0.0.0 - 5.4.14.1, 6.0 - 6.13.6.2 and 7.0 - 7.5.6.2. | 0.0.0 - 5.4.14.16.0 - 6.13.6.27.0 - 7.5.6.2 | Critical |
CVE-2022-25337 ezsystems/ezpublish-kernel is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 7.5.0 - 7.5.26. | 7.5.0 - 7.5.26 | Critical |
CVE-2021-46875 ezsystems/ezpublish-kernel is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 6.13.8.1 and 7.0.0 - 7.5.15.1. | 0.0.0 - 6.13.8.17.0.0 - 7.5.15.1 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
qafoo/rmf Version 1.0.* | — | — |
doctrine/dbal Version 2.5.*@beta | — | — |
symfony/symfony Version ~2.3 | — | — |
kriswallsmith/buzz Version >=0.9 | — | — |
nelmio/cors-bundle Version 1.3.* | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant