Habariproject maintains Habari, a modestly represented blogging and content-management platform with a focused vulnerability footprint centered on web application input handling and data exposure. The observed weaknesses cluster around cross-site scripting and improper handling of sensitive information disclosure, characteristic of application-layer flaws in content platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Habariproject over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4608MEDIUM Habari 0.6.5 allows remote attackers to obtain sensitive information via a direct request to (1) header.php and (2) comments_items.php in system/admin/, which reveals the installat | Dec 29, 2010 | 5.0 | 26 | NO | YES |
Multiple cross-site scripting (XSS) vulnerabilities in Habari 0.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) add | Dec 29, 2010 | 2.6 | 20 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Habariproject.
Media articles that mention a CVE ID that affects a product developed by Habariproject — matched by CVE ID, not by vendor name.