Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Infinite Automation Systems

First CVE: Jan 26, 2015Active for: 12 yearsTotal CVEs: 8

Infinite Automation Systems maintains Mango Automation, a web-based industrial control and data-acquisition platform deployed across operational-technology environments, whose vulnerability profile reflects the inherent risks of internet-facing automation software. The recurring weakness classes—including information disclosure, cross-site scripting, cross-site request forgery, OS command injection, and SQL injection—are characteristic of web application input handling and access control, spanning both client-side and server-side attack surfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
8.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
5.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Infinite Automation Systems over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2015
11 years ago
Most Recent CVE
Oct 28, 2015
3,926 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-7901MEDIUM
Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
Oct 28, 20156.533NOYES
CVE-2015-7904MEDIUM
Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary JSP cod
Oct 28, 20156.532NOYES
CVE-2015-7903MEDIUM
SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary SQL commands via u
Oct 28, 20156.532NOYES
CVE-2015-6493MEDIUM
Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to hijack the auth
Oct 28, 20156.826NOYES
CVE-2015-7902MEDIUM
Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed login attempts in unspecified circumstances, which allows r
Oct 28, 20155.023NOYES
CVE-2015-7900MEDIUM
Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive debugging information by entering a crafted URL to trigger a
Oct 28, 20154.322NOYES
CVE-2015-6494LOW
Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to inject arbitrary web sc
Oct 28, 20153.519NOYES
CVE-2015-1179MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in data_point_details.shtm in Mango Automation 2.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML v
Jan 26, 20154.319NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
13%
88%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
87.5% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Infinite Automation Systems.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Infinite Automation Systems — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Infinite Automation Systems's Products

View all 2 CNAs →

Top CWEs