Curveriderhq maintains Elgg, a social networking and community platform, where disclosed vulnerabilities center on path-traversal weaknesses that enable directory-escape attacks through improper pathname validation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Curveriderhq over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3149MEDIUM Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parame | Sep 10, 2009 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Curveriderhq.
Media articles that mention a CVE ID that affects a product developed by Curveriderhq — matched by CVE ID, not by vendor name.