Mambo
103 CVEs tracked since 2002. Since Mar 2002, none of them reached CISA KEV.
Mambo CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2002-03 | 1 | 0 |
| 2002-04 | null or fewer | |
| 2002-05 | null or fewer | |
| 2002-06 | null or fewer | |
| 2002-07 | null or fewer | |
| 2002-08 | null or fewer | |
| 2002-09 | null or fewer | |
| 2002-10 | null or fewer | |
| 2002-11 | null or fewer | |
| 2002-12 | null or fewer | |
| 2003-01 | null or fewer | |
| 2003-02 | null or fewer | |
| 2003-03 | null or fewer | |
| 2003-04 | null or fewer | |
| 2003-05 | null or fewer | |
| 2003-06 | null or fewer | |
| 2003-07 | null or fewer | |
| 2003-08 | null or fewer | |
| 2003-09 | null or fewer | |
| 2003-10 | null or fewer | |
| 2003-11 | null or fewer | |
| 2003-12 | null or fewer | |
| 2004-01 | null or fewer | |
| 2004-02 | null or fewer | |
| 2004-03 | null or fewer | |
| 2004-04 | null or fewer | |
| 2004-05 | null or fewer | |
| 2004-06 | null or fewer | |
| 2004-07 | null or fewer | |
| 2004-08 | null or fewer | |
| 2004-09 | null or fewer | |
| 2004-10 | null or fewer | |
| 2004-11 | null or fewer | |
| 2004-12 | null or fewer | |
| 2005-01 | null or fewer | |
| 2005-02 | 3 | 0 |
| 2005-03 | null or fewer | |
| 2005-04 | null or fewer | |
| 2005-05 | 5 | 0 |
| 2005-06 | 2 | 0 |
| 2005-07 | null or fewer | |
| 2005-08 | null or fewer | |
| 2005-09 | null or fewer | |
| 2005-10 | null or fewer | |
| 2005-11 | 2 | 0 |
| 2005-12 | null or fewer | |
| 2006-01 | null or fewer | |
| 2006-02 | 1 | 0 |
| 2006-03 | null or fewer | |
| 2006-04 | 2 | 0 |
| 2006-05 | null or fewer | |
| 2006-06 | 2 | 0 |
| 2006-07 | 5 | 0 |
| 2006-08 | 15 | 0 |
| 2006-09 | 3 | 0 |
| 2006-10 | null or fewer | |
| 2006-11 | null or fewer | |
| 2006-12 | null or fewer | |
| 2007-01 | null or fewer | |
| 2007-02 | null or fewer | |
| 2007-03 | 6 | 0 |
| 2007-04 | 3 | 0 |
| 2007-05 | 2 | 0 |
| 2007-06 | null or fewer | |
| 2007-07 | null or fewer | |
| 2007-08 | 3 | 0 |
| 2007-09 | 1 | 0 |
| 2007-10 | 5 | 0 |
| 2007-11 | null or fewer | |
| 2007-12 | 1 | 0 |
| 2008-01 | 8 | 0 |
| 2008-02 | 23 | 0 |
| 2008-03 | 3 | 0 |
| 2008-04 | null or fewer | |
| 2008-05 | 3 | 0 |
| 2008-06 | 1 | 0 |
| 2008-07 | 1 | 0 |
| 2008-08 | 1 | 0 |
| 2008-09 | null or fewer | |
| 2008-10 | null or fewer | |
| 2008-11 | 1 | 0 |
Products
The products that kept showing up in Mambo's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Mambo.
- CVE-2011-2499Mambo CMS through 4.6.5 has multiple XSS.6.1
- CVE-2013-2565A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.5.3
- CVE-2008-5226SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat parameter in a view ac...7.5
- CVE-2008-3712Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and 4.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) query strin...2.6
- CVE-2008-2990PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via...7.5
- CVE-2008-2905PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote attackers to execute ...6.8
- CVE-2008-2500Cross-site scripting (XSS) vulnerability in the MOStlyContent Editor (MOStlyCE) component before 3.0 for Mambo allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.4.3
- CVE-2008-2093SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter i...7.5
- CVE-2008-2095SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter.7.5
- CVE-2008-1540SQL injection vulnerability in the Datsogallery (com_datsogallery) 1.3.1 module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail acti...7.5
- CVE-2008-1297SQL injection vulnerability in index.php in the eWriting (com_ewriting) 1.2.1 module for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selec...7.5
- CVE-2008-1137SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id paramete...7.5
- CVE-2008-0854SQL injection vulnerability in the com_salesrep component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the rid parameter in a showrep action to index.php.7.5
- CVE-2008-0849SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a select...7.5
- CVE-2008-0855SQL injection vulnerability in the Facile Forms (com_facileforms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.7.5
The record
- Peak rank
- #2 in Feb 2008
- Busiest month shown
- Feb 2008, 23 CVEs
- Months with a KEV entry
- 0 since Mar 2002
- Monthly snapshots
- 26 since 2002