ibexa/admin-ui
Ibexa Admin Ui
Activity
- Latest release
- Jul 01, 2026
- Total releases
- 130
- Cadence
- ~18 days
- Last 12 months
- 16
Reach
- Stars
- 7
Details
- License
- GPL-2.0-only OR custom
- First release
- Nov 20, 2017
| Version | Released | |
|---|---|---|
v5.0.9
patch
|
v5.0.9
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
v4.6.31
patch
|
v4.6.31
patch
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
v5.0.8
patch
| ||
v4.6.30
patch
| ||
v5.0.7
patch
| ||
v4.6.29
patch
| ||
v5.0.6
patch
| ||
v4.6.28
patch
| ||
v4.6.27
patch
| ||
v5.0.5
patch
| ||
v5.0.4
patch
| ||
v4.6.26
patch
| ||
v5.0.3
patch
| ||
v4.6.25
patch
| ||
v5.0.2
patch
1 CVE
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v4.6.24
patch
1 CVE
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v5.0.1
patch
1 CVE
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v4.6.23
patch
1 CVE
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v4.6.22
patch
1 CVE
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v5.0.0
major
1 CVE
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v5.0.0-rc1
pre
|
v5.0.0-rc1
pre
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
v5.0.0-beta1
pre
|
v5.0.0-beta1
pre
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
v4.6.21
patch
1 CVE
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v4.6.20
patch
2 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.19
patch
2 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev |
v4.6.19
patch
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
v4.6.18
patch
2 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.17
patch
2 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.16
patch
2 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.15
patch
2 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.14
patch
2 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.13
patch
3 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.12
patch
3 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.11
patch
3 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.10
patch
3 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev |
v4.6.10
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
v4.6.9
patch
3 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.6.8
patch
4 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-39318
GHSA-qm44-wjm2-pr59
Jul 31, 2024
Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
Medium
Network
Low
Low
ImpactThe file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file. The fix ensures XSS is escaped. PatchesSee "Patched versions". Commit: https://github.com/ibexa/admin-ui/commit/8dc413fad1045fcfbe65dbcb0bea8516accc4c3e WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
+ 3 more Show less
v4.6.6
v4.6.7
v4.6.8
Fixed in
4.6.9
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.6.7
patch
4 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-39318
GHSA-qm44-wjm2-pr59
Jul 31, 2024
Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
Medium
Network
Low
Low
ImpactThe file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file. The fix ensures XSS is escaped. PatchesSee "Patched versions". Commit: https://github.com/ibexa/admin-ui/commit/8dc413fad1045fcfbe65dbcb0bea8516accc4c3e WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
+ 3 more Show less
v4.6.6
v4.6.7
v4.6.8
Fixed in
4.6.9
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.6.6
patch
4 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-39318
GHSA-qm44-wjm2-pr59
Jul 31, 2024
Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
Medium
Network
Low
Low
ImpactThe file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file. The fix ensures XSS is escaped. PatchesSee "Patched versions". Commit: https://github.com/ibexa/admin-ui/commit/8dc413fad1045fcfbe65dbcb0bea8516accc4c3e WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
+ 3 more Show less
v4.6.6
v4.6.7
v4.6.8
Fixed in
4.6.9
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.6.5
patch
4 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-39318
GHSA-qm44-wjm2-pr59
Jul 31, 2024
Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
Medium
Network
Low
Low
ImpactThe file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file. The fix ensures XSS is escaped. PatchesSee "Patched versions". Commit: https://github.com/ibexa/admin-ui/commit/8dc413fad1045fcfbe65dbcb0bea8516accc4c3e WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
+ 3 more Show less
v4.6.6
v4.6.7
v4.6.8
Fixed in
4.6.9
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.6.4
patch
4 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-39318
GHSA-qm44-wjm2-pr59
Jul 31, 2024
Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
Medium
Network
Low
Low
ImpactThe file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file. The fix ensures XSS is escaped. PatchesSee "Patched versions". Commit: https://github.com/ibexa/admin-ui/commit/8dc413fad1045fcfbe65dbcb0bea8516accc4c3e WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
+ 3 more Show less
v4.6.6
v4.6.7
v4.6.8
Fixed in
4.6.9
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.6.3
patch
4 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-39318
GHSA-qm44-wjm2-pr59
Jul 31, 2024
Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
Medium
Network
Low
Low
ImpactThe file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file. The fix ensures XSS is escaped. PatchesSee "Patched versions". Commit: https://github.com/ibexa/admin-ui/commit/8dc413fad1045fcfbe65dbcb0bea8516accc4c3e WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
+ 3 more Show less
v4.6.6
v4.6.7
v4.6.8
Fixed in
4.6.9
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.5.7
patch
|
v4.5.7
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
v4.6.2
patch
4 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-39318
GHSA-qm44-wjm2-pr59
Jul 31, 2024
Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
Medium
Network
Low
Low
ImpactThe file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file. The fix ensures XSS is escaped. PatchesSee "Patched versions". Commit: https://github.com/ibexa/admin-ui/commit/8dc413fad1045fcfbe65dbcb0bea8516accc4c3e WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
+ 3 more Show less
v4.6.6
v4.6.7
v4.6.8
Fixed in
4.6.9
References
Updated Feb 04, 2026 · Source: OSV.dev |
v4.6.2
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
v4.5.6
patch
| ||
v4.6.1
patch
4 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-39318
GHSA-qm44-wjm2-pr59
Jul 31, 2024
Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
Medium
Network
Low
Low
ImpactThe file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file. The fix ensures XSS is escaped. PatchesSee "Patched versions". Commit: https://github.com/ibexa/admin-ui/commit/8dc413fad1045fcfbe65dbcb0bea8516accc4c3e WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
+ 3 more Show less
v4.6.6
v4.6.7
v4.6.8
Fixed in
4.6.9
References
Updated Feb 04, 2026 · Source: OSV.dev |
v4.6.1
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
v4.6.0
minor
4 CVEs
GHSA-2mx6-fq24-g2mh
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in image asset names, content language names and future publishing in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-53864
GHSA-8w3p-gf85-qcch
Dec 02, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Medium
Network
Low
None
ImpactThe Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. Patches
WorkaroundsNone. References
Affected versions
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
+ 2 more Show less
v4.6.8
v4.6.9
Fixed in
4.6.14
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-39318
GHSA-qm44-wjm2-pr59
Jul 31, 2024
Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
Medium
Network
Low
Low
ImpactThe file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file. The fix ensures XSS is escaped. PatchesSee "Patched versions". Commit: https://github.com/ibexa/admin-ui/commit/8dc413fad1045fcfbe65dbcb0bea8516accc4c3e WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
+ 3 more Show less
v4.6.6
v4.6.7
v4.6.8
Fixed in
4.6.9
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.5.5
patch
|
v4.5.5
patch
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
v4.6.0-rc1
pre
2 CVEs
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-39318
GHSA-qm44-wjm2-pr59
Jul 31, 2024
Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
Medium
Network
Low
Low
ImpactThe file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file. The fix ensures XSS is escaped. PatchesSee "Patched versions". Commit: https://github.com/ibexa/admin-ui/commit/8dc413fad1045fcfbe65dbcb0bea8516accc4c3e WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
+ 3 more Show less
v4.6.6
v4.6.7
v4.6.8
Fixed in
4.6.9
References
Updated Feb 04, 2026 · Source: OSV.dev |
v4.6.0-rc1
pre
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
v4.6.0-beta5
pre
2 CVEs
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-39318
GHSA-qm44-wjm2-pr59
Jul 31, 2024
Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
Medium
Network
Low
Low
ImpactThe file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file. The fix ensures XSS is escaped. PatchesSee "Patched versions". Commit: https://github.com/ibexa/admin-ui/commit/8dc413fad1045fcfbe65dbcb0bea8516accc4c3e WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
+ 3 more Show less
v4.6.6
v4.6.7
v4.6.8
Fixed in
4.6.9
References
Updated Feb 04, 2026 · Source: OSV.dev |
v4.6.0-beta5
pre
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
v4.6.0-beta4
pre
2 CVEs
GHSA-5r6x-g6jv-4v87
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References Updated Jun 13, 2025 · Source: OSV.dev
CVE-2024-39318
GHSA-qm44-wjm2-pr59
Jul 31, 2024
Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
Medium
Network
Low
Low
ImpactThe file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file. The fix ensures XSS is escaped. PatchesSee "Patched versions". Commit: https://github.com/ibexa/admin-ui/commit/8dc413fad1045fcfbe65dbcb0bea8516accc4c3e WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
+ 3 more Show less
v4.6.6
v4.6.7
v4.6.8
Fixed in
4.6.9
References
Updated Feb 04, 2026 · Source: OSV.dev |