Known Vulnerabilities for products from Mambo

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Mambo".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2009-3434 json SQL injection vulnerability in the Tupinambis (com_tupinambis) component 1.0 for Mambo and Joomla! allows remote attackers to... Not Provided 2009-09-28 2026-04-23
CVE-2009-3333 json PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows remo... Not Provided 2009-09-23 2026-04-23
CVE-2009-0730 json Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_quotes... Not Provided 2009-02-24 2026-04-23
CVE-2009-0726 json SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to ex... Not Provided 2009-02-24 2026-04-23
CVE-2009-0706 json SQL injection vulnerability in the Simple Review (com_simple_review) component 1.3.5 for Joomla! and Mambo allows remote atta... Not Provided 2009-02-23 2026-04-23
CVE-2008-6814 json Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier f... Not Provided 2009-05-28 2026-04-23
CVE-2008-6653 json SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! ... Not Provided 2009-04-07 2026-04-23
CVE-2008-5643 json SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary SQL c... Not Provided 2008-12-17 2026-04-23
CVE-2008-5226 json SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers... Not Provided 2008-11-25 2026-04-23
CVE-2008-5208 json SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote at... Not Provided 2008-11-24 2026-04-23
CVE-2008-5200 json SQL injection vulnerability in the Xe webtv (com_xewebtv) component for Joomla! allows remote attackers to execute arbitrary ... Not Provided 2008-11-21 2026-04-23
CVE-2008-4777 json SQL injection vulnerability in the Showroom Joomlearn LMS (com_lms) component for Joomla! and Mambo allows remote attackers t... Not Provided 2008-10-29 2026-04-23
CVE-2008-3712 json Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and 4.6.5, when register_globals is enabled, allow remote ... Not Provided 2008-08-19 2026-04-23
CVE-2008-2990 json PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mam... Not Provided 2008-07-02 2026-04-23
CVE-2008-2905 json PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlie... Not Provided 2008-06-30 2026-04-23
CVE-2008-2500 json Cross-site scripting (XSS) vulnerability in the MOStlyContent Editor (MOStlyCE) component before 3.0 for Mambo allows remote ... Not Provided 2008-05-29 2026-04-23
CVE-2008-2095 json SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remote att... Not Provided 2008-05-06 2026-04-23
CVE-2008-2093 json SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows rem... Not Provided 2008-05-06 2026-04-23
CVE-2008-1849 json Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and ear... Not Provided 2008-04-16 2026-04-23
CVE-2008-1540 json SQL injection vulnerability in the Datsogallery (com_datsogallery) 1.3.1 module for Joomla! and Mambo allows remote attackers... Not Provided 2008-03-28 2026-04-23