Bluemoon develops a suite of web-based community and content-management modules, including blogging, file-upload, and survey functionality, where the observed vulnerability pattern centers on cross-site scripting weaknesses in web-page generation. This reflects the characteristic input-handling risks that arise in applications handling user-contributed content; live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bluemoon over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4053MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote attackers to inject arbitrary web script or | Sep 11, 2008 | 4.3 | 21 | NO | YES |
CVE-2008-2035MEDIUM Cross-site scripting (XSS) vulnerability in the Bluemoon, Inc. (1) BackPack 0.91 and earlier, (2) BmSurvey 0.84 and earlier, (3) newbb_fileup 1.83 and earlier, (4) News_embed (news | Apr 30, 2008 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bluemoon.
Media articles that mention a CVE ID that affects a product developed by Bluemoon — matched by CVE ID, not by vendor name.