CVE-2017-1000431: Ez Publish
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.
Affected products
- Ez Ez Publish: from 5.4.0, up to and including 5.4.9; up to and including 5.3.12
Published 2018-01-02. Last modified 2026-06-17.