ibexa/fieldtype-richtext
Ibexa RichText Extension, including the RichText FieldType.
Activity
- Latest release
- Jul 01, 2026
- Total releases
- 110
- Cadence
- ~18 days
- Last 12 months
- 16
Reach
- Stars
- 6
Details
- License
- unknown
- First release
- Nov 22, 2021
| Version | Released | |
|---|---|---|
v5.0.9
patch
|
v5.0.9
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
v4.6.31
patch
|
v4.6.31
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
v5.0.8
patch
| ||
v4.6.30
patch
| ||
v5.0.7
patch
| ||
v4.6.29
patch
| ||
v5.0.6
patch
| ||
v4.6.28
patch
| ||
v4.6.27
patch
| ||
v5.0.5
patch
| ||
v5.0.4
patch
| ||
v4.6.26
patch
| ||
v5.0.3
patch
| ||
v4.6.25
patch
| ||
v5.0.2
patch
1 CVE
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v4.6.24
patch
1 CVE
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v5.0.1
patch
1 CVE
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v4.6.23
patch
1 CVE
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v4.6.22
patch
1 CVE
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v5.0.0
major
1 CVE
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v5.0.0-rc1
pre
| ||
v5.0.0-beta1
pre
|
v5.0.0-beta1
pre
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
v4.6.21
patch
1 CVE
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev | ||
v4.6.20
patch
2 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.19
patch
2 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.18
patch
3 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
v4.6.17
patch
3 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
v4.6.16
patch
3 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
v4.6.15
patch
3 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
v4.6.14
patch
3 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
v4.6.13
patch
3 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
v4.6.12
patch
3 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
v4.6.11
patch
3 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
v4.6.10
patch
3 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev | ||
v4.6.9
patch
4 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev
CVE-2024-43369
GHSA-hvcf-6324-cjh7
Aug 14, 2024
Persistent Cross-site Scripting in Ibexa RichText Field Type
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactThe validator for the RichText fieldtype blocklists Patches
WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.10
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.6.8
patch
4 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev
CVE-2024-43369
GHSA-hvcf-6324-cjh7
Aug 14, 2024
Persistent Cross-site Scripting in Ibexa RichText Field Type
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactThe validator for the RichText fieldtype blocklists Patches
WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.10
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.6.7
patch
4 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev
CVE-2024-43369
GHSA-hvcf-6324-cjh7
Aug 14, 2024
Persistent Cross-site Scripting in Ibexa RichText Field Type
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactThe validator for the RichText fieldtype blocklists Patches
WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.10
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.6.6
patch
4 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev
CVE-2024-43369
GHSA-hvcf-6324-cjh7
Aug 14, 2024
Persistent Cross-site Scripting in Ibexa RichText Field Type
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactThe validator for the RichText fieldtype blocklists Patches
WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.10
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.6.5
patch
4 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev
CVE-2024-43369
GHSA-hvcf-6324-cjh7
Aug 14, 2024
Persistent Cross-site Scripting in Ibexa RichText Field Type
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactThe validator for the RichText fieldtype blocklists Patches
WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.10
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.6.4
patch
4 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev
CVE-2024-43369
GHSA-hvcf-6324-cjh7
Aug 14, 2024
Persistent Cross-site Scripting in Ibexa RichText Field Type
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactThe validator for the RichText fieldtype blocklists Patches
WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.10
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.6.3
patch
4 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev
CVE-2024-43369
GHSA-hvcf-6324-cjh7
Aug 14, 2024
Persistent Cross-site Scripting in Ibexa RichText Field Type
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactThe validator for the RichText fieldtype blocklists Patches
WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.10
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.5.7
patch
| ||
v4.6.2
patch
4 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev
CVE-2024-43369
GHSA-hvcf-6324-cjh7
Aug 14, 2024
Persistent Cross-site Scripting in Ibexa RichText Field Type
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactThe validator for the RichText fieldtype blocklists Patches
WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.10
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.5.6
patch
| ||
v4.6.1
patch
4 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev
CVE-2024-43369
GHSA-hvcf-6324-cjh7
Aug 14, 2024
Persistent Cross-site Scripting in Ibexa RichText Field Type
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactThe validator for the RichText fieldtype blocklists Patches
WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.10
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.6.0
minor
4 CVEs
GHSA-8c2g-f8jm-5cr7
Oct 17, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Medium
Network
Low
High
ImpactThis security advisory resolves an XSS vulnerability in acronym custom tag in Rich Text, in the back office of the DXP. Back office access and varying levels of editing and management permissions are required to exploit this vulnerability. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and may in some cases be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. PatchesSee "Patched versions". WorkaroundsNone. Referenceshttps://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office Affected versions
v5.0.0
v5.0.1
v5.0.2
v4.6.0
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
v4.6.14
v4.6.15
v4.6.16
+ 16 more Show less
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.21
v4.6.22
v4.6.23
v4.6.24
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.25
5.0.3
References Updated Oct 17, 2025 · Source: OSV.dev
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev
CVE-2024-43369
GHSA-hvcf-6324-cjh7
Aug 14, 2024
Persistent Cross-site Scripting in Ibexa RichText Field Type
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactThe validator for the RichText fieldtype blocklists Patches
WorkaroundsNone. References
CreditThis vulnerability was discovered and reported to Ibexa by Alec Romano: https://github.com/4rdr We thank them for reporting it responsibly to us. How to report security issues: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/ Affected versions
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.10
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
v4.5.5
patch
| ||
v4.6.0-rc1
pre
2 CVEs
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev |
v4.6.0-rc1
pre
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
v4.6.0-beta5
pre
2 CVEs
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev |
v4.6.0-beta5
pre
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
v4.6.0-beta4
pre
2 CVEs
GHSA-9qv6-4pwm-m68f
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 15 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev
GHSA-cj3w-g42v-wcj6
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
Network
Low
Low
None
ImpactThis security advisory resolves a vulnerability in the RichText field type. By entering a maliciously crafted input into the RichText XML, an attacker could perform an attack using XML external entity (XXE) injection, which might be able to read files on the server. To exploit this vulnerability the attacker would need to already have edit permission to content with RichText fields, which typically means Editor role or higher. The fix removes unsafe elements from XML code, while preserving safe elements. If you have a stored XXE attack in your content drafts, the fix prevents it from extracting data both during editing and preview. However, if such an attack has already been published and the result is stored in the content, it is unfortunately not possible to detect and remove it by automatic means. CreditsThis vulnerability was discovered and reported to Ibexa by Dennis Henke, Thorsten Niephaus, Marat Aytuganov, and Stephan Sekula of Compass Security Deutschland GmbH. We thank them for reporting it responsibly to us. Patches
Workarounds
References
Affected versions
v4.6.0
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
v4.6.13
+ 13 more Show less
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.19
References
Updated Apr 10, 2025 · Source: OSV.dev |