VendorsIbexaez_platformall versions
Vulnerabilities

Ibexa eZ Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2025-70363
Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.
Published 2026-03-06 · Modified
7.5EPSS 0.002
CVE-2022-48365
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.
Published 2023-03-12 · Modified
7.2EPSS 0.009
CVE-2022-48366
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack.
Published 2023-03-12 · Modified
3.7EPSS 0.005