CVE Tools

Lussumo

8 CVEs tracked since 2007. Since Oct 2007, none of them reached CISA KEV.

Lussumo CVEs per month

Oct 2007 to Apr 2010. Point at a month, or focus the strip and use the arrow keys.
Lussumo CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2007-1020
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-0840
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-02null or fewer
2009-03null or fewer
2009-04null or fewer
2009-05null or fewer
2009-0610
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-10null or fewer
2009-11null or fewer
2009-12null or fewer
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-0410

Products

The products that kept showing up in Lussumo's monthly top three, with their CVEs summed over those months.

  1. Vanilla84 months

Latest CVEs

The 9 most recently published vulnerabilities affecting Lussumo.

  1. CVE-2010-1337Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary PHP code via a UR...7.5
  2. CVE-2009-1845Cross-site scripting (XSS) vulnerability in ajax/updatecheck.php in Lussumo Vanilla 1.1.5 and 1.1.7 allows remote attackers to inject arbitrary web script or HTML via the RequestName parameter.4.3
  3. CVE-2008-3874Cross-site scripting (XSS) vulnerability in account.php in Lussumo Vanilla 1.1.5-rc1, 1.1.4, and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Value field...3.5
  4. CVE-2008-3760Cross-site request forgery (CSRF) vulnerability in the sign-out page in Vanilla 1.1.4 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a...4.3
  5. CVE-2008-3759Cross-site request forgery (CSRF) vulnerability in ajax/UpdateCheck.php in Vanilla 1.1.4 and earlier has unknown impact and remote attack vectors.7.5
  6. CVE-2008-3758Multiple cross-site scripting (XSS) vulnerabilities in Lussumo Vanilla 1.1.4 and earlier (1) allow remote attackers to inject arbitrary web script or HTML via the NewPassword parameter to people.ph...4.3
  7. CVE-2007-5644Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote attackers to conduct unauthorized sort operations...7.5
  8. CVE-2007-5643Multiple SQL injection vulnerabilities in Lussumo Vanilla 1.1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the CategoryID parameter to ajax/sortcategories.php or (...7.5
  9. CVE-2006-3850PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code via a URL in the ...5.1

The record

Peak rank
#17 in Aug 2008
Busiest month shown
Aug 2008, 4 CVEs
Months with a KEV entry
0 since Oct 2007
Monthly snapshots
4 since 2007
Lussumo's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store