← Back

Mambo Cms

mambo_cms

Vendor: Mambo Foundation • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mambo Foundation
1Mambo Cms
Nov 21, 2024
Feb 12, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Mambo CMS through 4.6.5 has multiple XSS.
1Mambo Foundation
1Mambo Cms
Nov 21, 2024
Feb 15, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.
1Mambo Foundation
1Mambo Cms
May 6, 2026
Jun 9, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.
1Mambo Foundation
1Mambo Cms
May 6, 2026
Jun 9, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file.
1Mambo Foundation
1Mambo Cms
May 6, 2026
Jun 9, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.