Exponent's vulnerability profile centers on a small and specialized content-management platform, where disclosures have concentrated on data-exposure and information-disclosure weaknesses. The vendor's vulnerabilities frequently acquire public exploit code, reflecting the appeal of CMS products to security researchers and the relative accessibility of web-application attack surfaces. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exponent over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4963MEDIUM Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence in the view para | Sep 23, 2006 | 6.4 | 28 | NO | YES |
CVE-2006-1604HIGH Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not "typecasted." | Apr 4, 2006 | 10.0 | 25 | NO | NO |
CVE-2005-3764HIGH The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview i | Nov 22, 2005 | 10.0 | 24 | NO | NO |
CVE-2007-2252MEDIUM Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive information via a .. (dot dot) in the icodi | Apr 25, 2007 | 5.0 | 23 | NO | YES |
CVE-2006-1605HIGH Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unknown vectors involving "parsed PHP." | Apr 4, 2006 | 7.5 | 20 | NO | NO |
CVE-2005-3765HIGH Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code. | Nov 22, 2005 | 7.5 | 20 | NO | NO |
CVE-2006-1607HIGH Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors. | Apr 4, 2006 | 7.5 | 19 | NO | NO |
CVE-2005-3762HIGH SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers to execute arbitrary SQL commands via the | Nov 22, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-0309MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module pa | Jan 25, 2005 | 4.3 | 18 | NO | NO |
CVE-2007-2253MEDIUM Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol.php and (2) sdk/blanks/file_modules.php | Apr 25, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exponent.
Media articles that mention a CVE ID that affects a product developed by Exponent — matched by CVE ID, not by vendor name.