Browse all 4 CVE security advisories affecting ibexa. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Ibexa is a digital experience platform enabling content management and e-commerce solutions. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from input validation flaws and misconfigurations. The platform has faced security incidents including authentication bypass issues and insecure direct object references. With four CVEs on record, security concerns typically revolve around improper access controls and session management weaknesses. Organizations implementing Ibexa should prioritize regular security assessments and ensure proper configuration to mitigate risks associated with these common vulnerability classes.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-53864 | Cross-site Scripting in a field that is used in the Content name pattern in ibexa/admin-ui — admin-uiCWE-79 | 5.4 | - | 2024-11-29 |
| CVE-2024-39318 | Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget — admin-uiCWE-79 | 5.4 | Medium | 2024-07-31 |
This page lists every published CVE security advisory associated with ibexa. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.