Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mambo

First CVE: Jul 25, 2001Active for: 25 yearsTotal CVEs: 175
50.1
VTI Score
TOP TARGET

Mambo's vulnerability footprint spans a modestly represented portfolio of open-source and commercial content-management and web-application systems, with a presence more prominent than most in the vulnerability landscape. The vendor's recurring exposure centers on application-layer input-handling flaws endemic to dynamic web platforms: SQL injection, cross-site scripting, path traversal, and code injection vulnerabilities appear consistently across flagship products such as Mambo, Mambo Site Server, and its component ecosystem including downloads and form-handling extensions. While severity tends toward moderate outcomes, the vendor's vulnerabilities frequently acquire public exploit code, reflecting both the accessibility of web-application attack tooling and the target appeal of deployed instances. Defenders should treat this vendor's security updates as routine and prioritize patching internet-exposed Mambo installations and custom components; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
149
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mambo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 25, 2001
24 years ago
Most Recent CVE
Feb 12, 2020
2,354 days ago

Products(65 total)

Top CVEs

Signals from CVEs in this vendor scope (149 CVEs).

149 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-5362MEDIUM
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute
Oct 11, 20076.850NOYES
CVE-2008-2905MEDIUM
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote atta
Jun 30, 20086.843NOYES
CVE-2007-1699HIGH
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary
Mar 27, 200710.043NOYES
CVE-2003-1245HIGH
index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie.
Dec 31, 200310.042NOYES
CVE-2007-2005MEDIUM
Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosCo
Apr 12, 20076.836NOYES
CVE-2007-1596HIGH
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP
Mar 22, 20079.336NOYES
CVE-2008-1465HIGH
SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id pa
Mar 24, 20089.335NOYES
CVE-2006-4296HIGH
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers to include arbitrary files via the mosCon
Aug 23, 20067.535NOYES
CVE-2011-2917HIGH
SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the zorder parameter.
Dec 8, 20117.534NOYES
CVE-2008-0772HIGH
SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view ta
Feb 14, 20087.533NOYES
View all 149 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products149 CVEs
33%
64%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (2.0%)
Unknown146 (98.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (2.0%)
High0 (0.0%)
Unknown146 (98.0%)
User Interaction
None2 (1.3%)
Unknown146 (98.0%)
Required1 (0.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (2.0%)
Unknown146 (98.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (149 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
104 CVEs
69.8% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mambo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mambo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mambo's Products

View all 3 CNAs →

Top CWEs