CVE-2022-25337: Ibexa Ez Platform Kernel

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.

Affected products

  • Ibexa Ez Platform Kernel: from 1.3.0, before 1.3.12 (fixed in 1.3.12); from 7.5.0, before 7.5.26 (fixed in 7.5.26)

Published 2022-02-18. Last modified 2026-06-17.