Fuzzylime's vulnerability profile centers on its content-management system and related web applications, which recur across a narrow but prominent product line and are characterized by application-layer input-handling and path-access weaknesses. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility and weaponizability of typical CMS flaws such as path traversal, code injection, and cross-site scripting. Defenders should treat Fuzzylime CMS deployments as requiring prompt patching attention when advisories emerge; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fuzzylime over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1405MEDIUM PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter. | Mar 20, 2008 | 6.8 | 46 | NO | YES |
CVE-2008-6833HIGH Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a files | Jun 22, 2009 | 10.0 | 38 | NO | YES |
CVE-2008-6834HIGH Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the s p | Jun 22, 2009 | 10.0 | 36 | NO | YES |
CVE-2009-2176HIGH Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local | Jun 23, 2009 | 7.5 | 31 | NO | YES |
CVE-2007-4805HIGH Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the p paramet | Sep 11, 2007 | 7.5 | 31 | NO | YES |
CVE-2008-3164HIGH Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a | Jul 14, 2008 | 7.6 | 29 | NO | YES |
CVE-2009-2177MEDIUM code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary fil | Jun 23, 2009 | 6.8 | 28 | NO | YES |
CVE-2008-5291HIGH Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the | Dec 1, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3165MEDIUM Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local | Jul 14, 2008 | 6.8 | 27 | NO | YES |
CVE-2008-3098MEDIUM Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers to inject arbitrary web script or HTML via the user parameter | Sep 24, 2008 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fuzzylime.
Media articles that mention a CVE ID that affects a product developed by Fuzzylime — matched by CVE ID, not by vendor name.