CVE-2022-25337: Ibexa Ez Platform Kernel
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.
Affected products
- Ibexa Ez Platform Kernel: from 1.3.0, before 1.3.12 (fixed in 1.3.12); from 7.5.0, before 7.5.26 (fixed in 7.5.26)
Published 2022-02-18. Last modified 2026-06-17.