Lyris develops List Manager, an email marketing and list-management platform whose vulnerability profile centers on web-application input handling, particularly cross-site scripting issues inherent to user-facing web interfaces that generate and serve dynamic content. Despite a narrowly scoped product portfolio, the vendor's disclosures frequently acquire public exploit tooling, reflecting the accessibility and attractiveness of web-application flaws to automated scanning and testing. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lyris over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4143HIGH SQL injection vulnerability in Lyris ListManager 5.0 through 8.9a allows remote attackers to execute arbitrary SQL commands via SQL code after a numeric argument to a /read/attachm | Dec 10, 2005 | 7.5 | 28 | NO | YES |
CVE-2007-6319HIGH Multiple unspecified vulnerabilities in Lyris ListManager 8.x before 8.95d, 9.2 before 9.2c, and 9.3 before 9.3b allow remote attackers to (1) gain list administrator privileges or | Feb 19, 2008 | 10.0 | 27 | NO | NO |
CVE-2005-4144HIGH Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines | Dec 10, 2005 | 7.5 | 20 | NO | NO |
CVE-2006-4547MEDIUM Lyris ListManager 8.95 allows remote authenticated users to obtain sensitive information by attempting to add a user with a ' (single quote) character in the name, which reveals th | Sep 6, 2006 | 6.5 | 19 | NO | NO |
CVE-2014-5188MEDIUM Cross-site scripting (XSS) vulnerability in doemailpassword.tml in Lyris ListManager (LM) 8.95a allows remote attackers to inject arbitrary web script or HTML via the EmailAddr par | Aug 7, 2014 | 4.3 | 18 | NO | NO |
CVE-2006-4546MEDIUM Lyris ListManager 8.95 allows remote authenticated users, who have administrative privileges for at least one list on the server, to add new administrators to any list via a modifi | Sep 6, 2006 | 6.5 | 18 | NO | NO |
CVE-2008-2923MEDIUM Cross-site scripting (XSS) vulnerability in read/search/results in Lyris ListManager 8.8, 8.95, and 9.3d allows remote attackers to inject arbitrary web script or HTML via the word | Jun 30, 2008 | 4.3 | 14 | NO | NO |
CVE-2000-0758MEDIUM The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying the value of the list_admin hidden form field. | Oct 20, 2000 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lyris.
Media articles that mention a CVE ID that affects a product developed by Lyris — matched by CVE ID, not by vendor name.