Jupo maintains a narrowly scoped product portfolio centered on the Mezzanine content management system, which despite modest volume commands attention for its deployment in web-publishing and editorial workflows. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with recurrent exposure concentrated in input-handling and access-control defects such as cross-site scripting flaws and improper authorization logic. Defenders should treat Mezzanine advisories as security-priority items for affected instances; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jupo over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50481MEDIUM A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a cra | Jul 23, 2025 | 4.8 | 28 | NO | YES |
CVE-2024-25170CRITICAL An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header. | Feb 28, 2024 | 9.1 | 28 | NO | NO |
CVE-2024-25169CRITICAL An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request. | Feb 28, 2024 | 9.8 | 25 | NO | NO |
CVE-2020-19002MEDIUM Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the 'Description' field of the component 'admin/blog/blogpost/add/'. This issue | Aug 27, 2021 | 6.1 | 22 | NO | NO |
CVE-2018-16632MEDIUM Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blog/blogpost/add/. | Dec 28, 2018 | 4.8 | 19 | NO | NO |
CVE-2025-29573MEDIUM Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module. | May 5, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-6050MEDIUM Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the "displayable_links_js" | Jun 17, 2025 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jupo.
Media articles that mention a CVE ID that affects a product developed by Jupo — matched by CVE ID, not by vendor name.