CVE-2014-2729: Ektron Content Management System

Low severity, CVSS 3.5. EPSS: 1% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS 8.7 before 8.7.0.055 allows remote authenticated users to inject arbitrary web script or HTML via the category0 parameter, which is not properly handled when displaying the Subjects tab in the View Properties menu option.

Affected products

  • Ektron Ektron Content Management System: version 8.7.0 only

Published 2014-04-25. Last modified 2026-06-17.