Majordomo
This hub aggregates every CVE we track for Majordomo, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
4
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7MEDIUM4CRITICAL4
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
8
0
0
0
0
0
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Majordomo.
- CVE-2026-27180MajorDoMo Supply Chain Remote Code Execution via Update URL Poisoning9.8
- CVE-2026-27181MajorDoMo Unauthenticated Module Uninstall via Market Endpoint7.5
- CVE-2026-27179MajorDoMo Unauthenticated SQL Injection in Commands Module8.2
- CVE-2026-27178MajorDoMo Stored Cross-Site Scripting via Method Parameters to Shoutbox7.2
- CVE-2026-27177MajorDoMo Stored Cross-Site Scripting via Property Set Endpoint7.2
- CVE-2026-27176MajorDoMo Reflected Cross-Site Scripting in command.php6.1
- CVE-2026-27174MajorDoMo Unauthenticated Remote Code Execution via Admin Console Eval9.8
- CVE-2026-27175MajorDoMo Command Injection in rc/index.php via Race Condition9.8
- CVE-2023-50917MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.9.8
- CVE-2010-0345Cross-site scripting (XSS) vulnerability in the Majordomo extension 1.1.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.4.3
- CVE-2003-1367The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of m...7.8
- CVE-1999-1220Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply...7.5
- CVE-2000-0037Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.4.6
- CVE-2000-0035resend command in Majordomo allows local users to gain privileges via shell metacharacters.4.6
- CVE-1999-0207Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.7.5
Product normalization is registry-driven with AI assist and human review. How it works