H Fj maintains a narrow portfolio of web-accessible plugins and server utilities, primarily mailform and PHP-related components that handle user input and server-side scripting. The observed vulnerability exposure reflects vulnerabilities affecting these application-layer products. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by H Fj over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2945HIGH mt-phpincgi.php in Hajime Fujimoto mt-phpincgi before 2015-05-15 does not properly restrict URLs, which allows remote attackers to conduct PHP object injection attacks and execute | May 25, 2015 | 7.5 | 19 | NO | NO |
CVE-2007-6751MEDIUM Cross-site scripting (XSS) vulnerability in the MailForm plugin before 1.20 for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jan 4, 2012 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by H Fj.
Media articles that mention a CVE ID that affects a product developed by H Fj — matched by CVE ID, not by vendor name.