Mambo Foundation maintains a small but historically prominent content-management system that has been widely adopted across small-to-medium web properties and community sites. The vendor's vulnerability disclosures concentrate around its core Mambo CMS product and related extensions, reflecting the typical input-handling and access-control attack surface of web-application platforms. While the vendor's CVE footprint is modest in volume relative to larger platforms, its presence in the vulnerability landscape reflects the product's enduring deployment in legacy and specialized web environments. Defenders managing Mambo installations should prioritize inventory and lifecycle assessment, particularly for aging deployments; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mambo Foundation over time
Signals from CVEs in this vendor scope (149 CVEs).
149 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5362MEDIUM Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute | Oct 11, 2007 | 6.8 | 50 | NO | YES |
CVE-2008-2905MEDIUM PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote atta | Jun 30, 2008 | 6.8 | 43 | NO | YES |
CVE-2007-1699HIGH Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary | Mar 27, 2007 | 10.0 | 43 | NO | YES |
CVE-2003-1245HIGH index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie. | Dec 31, 2003 | 10.0 | 42 | NO | YES |
CVE-2007-2005MEDIUM Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosCo | Apr 12, 2007 | 6.8 | 36 | NO | YES |
CVE-2007-1596HIGH Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP | Mar 22, 2007 | 9.3 | 36 | NO | YES |
CVE-2008-1465HIGH SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id pa | Mar 24, 2008 | 9.3 | 35 | NO | YES |
CVE-2006-4296HIGH PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers to include arbitrary files via the mosCon | Aug 23, 2006 | 7.5 | 35 | NO | YES |
CVE-2011-2917HIGH SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the zorder parameter. | Dec 8, 2011 | 7.5 | 34 | NO | YES |
CVE-2008-0772HIGH SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view ta | Feb 14, 2008 | 7.5 | 33 | NO | YES |
Signals from CVEs in this vendor scope (149 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mambo Foundation.
Media articles that mention a CVE ID that affects a product developed by Mambo Foundation — matched by CVE ID, not by vendor name.