Blaine Lang develops a focused portfolio of web-based collaboration and file-management applications, including Maestro and FileDepot, with a durable pattern of web-layer input-handling vulnerabilities centered on cross-site request forgery and cross-site scripting. These weakness classes reflect the attack surface of browser-facing applications where request validation and output encoding are critical to defense. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blaine Lang over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-3799MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allow remote attackers to hijack the authentication of administra | Jun 27, 2012 | 5.1 | 17 | NO | NO |
CVE-2012-2719MEDIUM The filedepot module 6.x-1.x before 6.x-1.3 for Drupal, when accessed using multiple different browsers from the same IP address, causes Internet Explorer sessions to "switch users | Jun 27, 2012 | 5.1 | 17 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with maestro admin permissions to inject arbitrar | Jun 27, 2012 | 2.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blaine Lang.
Media articles that mention a CVE ID that affects a product developed by Blaine Lang — matched by CVE ID, not by vendor name.