What an Outdated ExpressionEngine or Craft CMS Install Actually Exposes You To

What an Outdated ExpressionEngine or Craft CMS Install Actually Exposes You To

ExpressionEngineCraft CMSMisc By Karl Bowers

An unpatched CMS install carries a list of known weaknesses that anyone can look up. Once a version stops receiving security updates, that list only gets longer.

This pattern shows up repeatedly in the security reviews we run on ExpressionEngine and Craft CMS sites. It's consistent enough to be worth explaining plainly.

What "end of life" actually means

Every piece of software eventually stops receiving security updates from its maker. For a CMS, that moment matters more than for most software, because the CMS controls your login system, your database, and often your customer data in one place.

Once a version reaches that point, every flaw discovered in it stays there permanently. There's no patch coming. And because the flaw gets publicly documented (that's how security researchers report these things), anyone can find out exactly what it is and how to use it. Finding this kind of exposure doesn't take a targeted attack. Automated tools scan the web for it all day, every day.

What this looks like in practice

A few examples, all real patterns we've found on live sites, not hypothetical:

  • A flaw in how a CMS handles new member registration lets an attacker manipulate the database before they've even logged in.
  • A flaw in an admin editing tool lets a logged-in account run code on the server it was never meant to run.
  • An old server feature nobody uses anymore, still switched on by default, gives an attacker a route to execute commands directly.

Exploiting any of these takes nothing more than software old enough that the fix was never applied.

It's rarely just the software

The version number is the headline finding, but it's rarely the only one. The same review usually turns up smaller issues that have quietly accumulated over years: login credentials for the live database sitting in the code repository, upload folders that will run any file placed in them, cookies that don't force a secure connection.

Each of these looks minor in isolation. Together, they lower the bar for an attacker considerably. A stolen password or a single compromised account can go a lot further on a site with three or four of these gaps open than on one with none.

The part that catches people off guard

One finding almost always has the same shape. A decision made years ago, reasonable at the time, that nobody has looked at since. A document folder made publicly accessible because it was easier, a security control switched off during a migration and never switched back on, a rule that was fine when the site was smaller and matters more now that it isn't.

The person who inherits a site rarely knows these decisions were made. That's what makes a proper review worth doing even when nothing looks obviously wrong. It's usually several small gaps, each acceptable on its own at the time it was made, adding up quietly over years.

What it actually costs

A breach on a business-critical site costs more than downtime. Customer or member data can be exposed, investigating what happened takes real time and money, and in the UK there's a possible obligation to report it. None of that is quick to resolve, and all of it happens under pressure, usually while the site is also down.

The cost of fixing an outdated install ahead of time is a fraction of the cost of responding to an incident after the fact.

How to find out where you stand

A proper security review checks more than the CMS version number. It looks at what's actually configured: how passwords are stored, whether upload folders can execute files, whether credentials are exposed anywhere in the code, and what protection is actually active versus switched on but never configured.

If you don't know the answer to most of those questions, that's worth finding out before it's forced on you. We offer a security and technical audit that reviews exactly this, on both ExpressionEngine and Craft CMS. Get in touch and we'll tell you plainly what we find.

Topics ExpressionEngine Craft CMS Misc

Related Services

ExpressionEngine Maintenance, Upgrade & Support Craft CMS Maintenance, Upgrade & Support Ongoing Maintenance & Support Taking Over From a Previous Developer

Related Case Studies

Graham Sanderson Interiors ~ A Luxury Interior Design Retailer City Permits ~ A UK Parking Enforcement Operator

More posts

View all posts

Can we help?

Most clients come to us when their site has started to feel like a risk rather than an asset. Whether the agency relationship has ended, an upgrade has been delayed, or the site has simply grown beyond what it can handle, a conversation costs nothing.

Get in touch with Karl

Trusted by established businesses and growing brands across the UK

Expression 37 works with a small number of clients at any one time. These are some of them.

About Karl

Karl Bowers ~ ExpressionEngine & Craft CMS Specialist

Karl founded Expression 37 in 2007 and has worked exclusively with ExpressionEngine and Craft CMS ever since. He does not take on work in other platforms and does not hand work to other developers. Expression 37 is deliberately small, because the kind of support that matters to clients with business-critical sites is specific to their site, not something that scales in the conventional sense. If you work with Expression 37, you work with Karl.

Find out how we work

Client feedback:

Karl at Expression 37 has been essential in keeping our Craft CMS website running at its best. His regular updates and fine-tuning ensure that our site is always up-to-date, secure, and optimised for performance. Karl’s expertise and attention to detail mean we can rely on him for everything from routine maintenance to customised site tweaks. It’s a relief to know our website is in such capable hands with Expression 37. Highly recommended!

Kimberley Clayton-Bull ~ Head of Marketing & Communications
Capula

» Get in touch