Mozilo
11 CVEs tracked since 2008. Since Aug 2008, none of them reached CISA KEV.
Mozilo CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2008-08 | 1 | 0 |
| 2008-09 | null or fewer | |
| 2008-10 | null or fewer | |
| 2008-11 | null or fewer | |
| 2008-12 | null or fewer | |
| 2009-01 | null or fewer | |
| 2009-02 | 6 | 0 |
| 2009-03 | null or fewer | |
| 2009-04 | 3 | 0 |
| 2009-05 | null or fewer | |
| 2009-06 | null or fewer | |
| 2009-07 | null or fewer | |
| 2009-08 | null or fewer | |
| 2009-09 | null or fewer | |
| 2009-10 | null or fewer | |
| 2009-11 | null or fewer | |
| 2009-12 | 1 | 0 |
Products
The products that kept showing up in Mozilo's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Mozilo.
- CVE-2024-44871An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.7.2
- CVE-2024-44872A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.6.1
- CVE-2024-29368An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file ex...6.5
- CVE-2024-2245Cross-Site Scripting vulnerability in moziloCMS5.4
- CVE-2022-23357mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.9.1
- CVE-2020-25394A stored cross site scripting (XSS) vulnerability in moziloCMS 2.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Content" parameter.5.4
- CVE-2009-4209Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) file parameters in a...4.3
- CVE-2009-1369moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter to index.php, or (4) file[] parameter to downlo...5.0
- CVE-2009-1368Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. NOTE: this might be the same issue as CVE...7.5
- CVE-2009-1367Cross-site scripting (XSS) vulnerability in index.php in moziloCMS 1.11 allows remote attackers to inject arbitrary web script or HTML via the query parameter in search action, a different issue th...4.3
- CVE-2008-6129Directory traversal vulnerability in print.php in moziloWiki 1.0.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.4.3
- CVE-2008-6127Multiple cross-site scripting (XSS) vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) query parameters to (a) in...4.3
- CVE-2008-6131Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.6.0
- CVE-2008-6130Cross-site scripting (XSS) vulnerability in index.php in moziloWiki 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) action and (2) page parameters.4.3
- CVE-2008-6126Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to download.php and the (2) ...5.0
The record
- Peak rank
- #15 in Feb 2009
- Busiest month shown
- Feb 2009, 6 CVEs
- Months with a KEV entry
- 0 since Aug 2008
- Monthly snapshots
- 4 since 2008