Carbon Communities maintains a focused sustainability and environmental-impact platform with a narrow product footprint. The recorded disclosures are constrained in scope and characterized by placeholder weakness classifications, indicating limited technical detail available in the vulnerability record; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Carbon Communities over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1895HIGH Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to events.asp, the (2 | Apr 18, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-1896MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect paramet | Apr 18, 2008 | 4.3 | 21 | NO | YES |
CVE-2008-1900HIGH option_Update.asp in Carbon Communities 2.4 and earlier allows remote attackers to edit arbitrary member information via a modified ID field. | Apr 22, 2008 | 7.5 | 19 | NO | NO |
CVE-2007-0096HIGH CarbonCommunities stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a | Jan 5, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Carbon Communities.
Media articles that mention a CVE ID that affects a product developed by Carbon Communities — matched by CVE ID, not by vendor name.