CVE Tools

Mambo

103 CVEs tracked since 2002. Since Mar 2002, none of them reached CISA KEV.

Mambo CVEs per month

Mar 2002 to Nov 2008. Point at a month, or focus the strip and use the arrow keys.
Mambo CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2002-0310
2002-04null or fewer
2002-05null or fewer
2002-06null or fewer
2002-07null or fewer
2002-08null or fewer
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-04null or fewer
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-0230
2005-03null or fewer
2005-04null or fewer
2005-0550
2005-0620
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-1120
2005-12null or fewer
2006-01null or fewer
2006-0210
2006-03null or fewer
2006-0420
2006-05null or fewer
2006-0620
2006-0750
2006-08150
2006-0930
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-0360
2007-0430
2007-0520
2007-06null or fewer
2007-07null or fewer
2007-0830
2007-0910
2007-1050
2007-11null or fewer
2007-1210
2008-0180
2008-02230
2008-0330
2008-04null or fewer
2008-0530
2008-0610
2008-0710
2008-0810
2008-09null or fewer
2008-10null or fewer
2008-1110

Products

The products that kept showing up in Mambo's monthly top three, with their CVEs summed over those months.

  1. Mambo2316 months
  2. Mambo Site Server75 months
  3. Mambo Open Source65 months
  4. Com Downloads21 month
  5. Mambo Calendar22 months
  6. Mambo Gallery Manager21 month
  7. Artlinks Component11 month
  8. Bayesiannaivefilter11 month
  9. Com Comprofiler11 month
  10. Com Comprofiler Component11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Mambo.

  1. CVE-2011-2499Mambo CMS through 4.6.5 has multiple XSS.6.1
  2. CVE-2013-2565A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.5.3
  3. CVE-2008-5226SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat parameter in a view ac...7.5
  4. CVE-2008-3712Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and 4.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) query strin...2.6
  5. CVE-2008-2990PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via...7.5
  6. CVE-2008-2905PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote attackers to execute ...6.8
  7. CVE-2008-2500Cross-site scripting (XSS) vulnerability in the MOStlyContent Editor (MOStlyCE) component before 3.0 for Mambo allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.4.3
  8. CVE-2008-2093SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter i...7.5
  9. CVE-2008-2095SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter.7.5
  10. CVE-2008-1540SQL injection vulnerability in the Datsogallery (com_datsogallery) 1.3.1 module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail acti...7.5
  11. CVE-2008-1297SQL injection vulnerability in index.php in the eWriting (com_ewriting) 1.2.1 module for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selec...7.5
  12. CVE-2008-1137SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id paramete...7.5
  13. CVE-2008-0854SQL injection vulnerability in the com_salesrep component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the rid parameter in a showrep action to index.php.7.5
  14. CVE-2008-0849SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a select...7.5
  15. CVE-2008-0855SQL injection vulnerability in the Facile Forms (com_facileforms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.7.5

The record

Peak rank
#2 in Feb 2008
Busiest month shown
Feb 2008, 23 CVEs
Months with a KEV entry
0 since Mar 2002
Monthly snapshots
26 since 2002
Mambo's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store