Futomi develops a focused portfolio of CGI-based web utilities and analysis tools, including the widely used mp_form_mail_cgi, access_analyzer_cgi, and cgi_cafe_access_analyzer_cgi, which sit in request-handling positions where input-validation flaws compound exposure. Vulnerabilities affecting this vendor skew toward serious outcomes and recur through characteristic web-application weakness classes: cross-site scripting, code injection, path traversal, and authentication bypass, reflecting the parsing and access-control demands of CGI scripts exposed to untrusted input. Defenders should prioritize inventory and patching of these utilities given their prevalence in legacy web deployments; live severity and current vulnerability counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Futomi over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0514CRITICAL MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. | Feb 8, 2018 | 9.8 | 30 | NO | NO |
CVE-2015-0898HIGH futomi CGI Cafe MP Form Mail CGI eCommerce before 2.0.12 on Windows allows remote attackers to execute arbitrary Perl code via unspecified vectors. | Mar 21, 2015 | 7.5 | 20 | NO | NO |
CVE-2009-1206HIGH Unspecified vulnerability in futomi's CGI Cafe Access Analyzer CGI Professional Version 4.11.5 and earlier allows remote attackers to gain administrative privileges via unknown vec | Apr 1, 2009 | 7.5 | 19 | NO | NO |
CVE-2009-0962HIGH Unspecified vulnerability in Futomi's CGI Cafe MP Form Mail CGI eCommerce 1.3.0 and earlier, and CGI Professional 3.2.2 and earlier, allows remote attackers to gain administrative | Mar 19, 2009 | 7.5 | 19 | NO | NO |
CVE-2010-2366MEDIUM Cross-site scripting (XSS) vulnerability in futomi CGI Cafe Access Analyzer CGI Professional, and Standard 4.0.2 and earlier, allows remote attackers to inject arbitrary web script | Sep 13, 2010 | 4.3 | 16 | NO | NO |
CVE-2008-5809MEDIUM futomi CGI Cafe Access Analyzer CGI Standard 4.0.1 and earlier and Access Analyzer CGI Professional 4.11.3 and earlier use a predictable session id, which makes it easier for remot | Jan 2, 2009 | 5.8 | 16 | NO | NO |
CVE-2009-0971MEDIUM Cross-site scripting (XSS) vulnerability in futomi's CGI Cafe Access Analyzer CGI Standard Version 3.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML | Mar 19, 2009 | 4.3 | 14 | NO | NO |
Directory traversal vulnerability in futomi MP Form Mail CGI Professional Edition 3.2.3 and earlier allows remote authenticated administrators to read arbitrary files via unspecifi | Jun 5, 2016 | 2.7 | 12 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Futomi.
Media articles that mention a CVE ID that affects a product developed by Futomi — matched by CVE ID, not by vendor name.