Lullabot develops the Fivestar module for Drupal, a community-contributed rating and voting extension that adds interactive feedback functionality to Drupal sites. The module's observed vulnerability exposure centers on cross-site request forgery and improper input validation, reflecting typical risks in form-handling and user-interaction components within the Drupal ecosystem. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lullabot over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2096MEDIUM The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in t | Aug 14, 2012 | 5.0 | 18 | NO | NO |
CVE-2009-2572MEDIUM Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allows remote attackers to hijack t | Jul 22, 2009 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lullabot.
Media articles that mention a CVE ID that affects a product developed by Lullabot — matched by CVE ID, not by vendor name.