CVE-2010-2671
eZ Publish <4.2.0 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitrary web script or HTML via the subTreeItem parameter.
References (7)
Scores
EPSS
0.0052
EPSS Percentile
66.3%
Classification
CWE
CWE-79
Status
published
Affected Products (15)
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
n/a/n/a
Timeline
Published
Jul 08, 2010
Tracked Since
Feb 18, 2026