ExpressionengineCVEs & Vulnerabilities

14 CVEs affecting Expressionengine products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

expressionengine 111
CVE-2025-59473HIGH

SQL Injection vulnerability in the Structure for Admin authenticated user

27 Jan 2026
7.2
CVSS
CVE-2024-38454MEDIUM

ExpressionEngine before 7.4.11 allows XSS.

16 Jun 2024
6.1
CVSS
CVE-2023-22953HIGH

In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user.

9 Feb 2023
8.8
CVSS
CVE-2020-8242HIGH

Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to execute the attack.

18 Feb 2022
7.2
CVSS
CVE-2021-33199CRITICAL

In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file names of icon.png and icon.svg.

13 Aug 2021
9.8
CVSS
CVE-2021-27230HIGH

ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/language directory.

16 Mar 2021
8.8
CVSS
CVE-2020-13443HIGH

ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft actions. A user with low privileges (member) is able to upload this. It is possible to bypass the MIME type check and file-extension check while uploading new files. Short aliases are not used for an attachment; instead, direct access is allowed to the uploaded files. It is possible to upload PHP only if one has member access, or registration/forum is enabled and one can create a member with the default group id of 5. To exploit this, one must to be able to send and compose messages (at least).

24 Jun 2020
8.8
CVSS
CVE-2018-17874MEDIUM

ExpressionEngine before 4.3.5 has reflected XSS.

2 Oct 2018
6.1
CVSS
CVE-2017-1000160MEDIUM

EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection

17 Nov 2017
5.4
CVSS
CVE-2017-0897HIGH

ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.

23 Jun 2017
7.5
CVSS
CVE-2014-5387MEDIUM

Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) category[] parameter to system/index.php or the (3) tbl_sort[0][] parameter in the comment module to system/index.php.

4 Nov 2014
6.5
CVSS
CVE-2009-1070MEDIUMpoc

Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter.

26 Mar 2009
4.3
CVSS
CVE-2008-0202MEDIUM

CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter.

10 Jan 2008
4.3
CVSS
CVE-2008-0201MEDIUM

Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameter.

10 Jan 2008
4.3
CVSS
← PrevPage 1 / 1Next →
Expressionengine CVEs & Vulnerabilities — 14 Tracked