Mambo cms
This hub aggregates every CVE we track for Mambo cms, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM3LOW2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 5 most recently published vulnerabilities affecting Mambo cms.
- CVE-2011-2499Mambo CMS through 4.6.5 has multiple XSS.6.1
- CVE-2013-2565A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.5.3
- CVE-2013-2564Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.5.0
- CVE-2013-2563Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file.2.1
- CVE-2013-2562Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.2.1
Product normalization is registry-driven with AI assist and human review. How it works