Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mambo Foundation

First CVE: Jul 25, 2001Active for: 25 yearsTotal CVEs: 175

Mambo Foundation maintains a small but historically prominent content-management system that has been widely adopted across small-to-medium web properties and community sites. The vendor's vulnerability disclosures concentrate around its core Mambo CMS product and related extensions, reflecting the typical input-handling and access-control attack surface of web-application platforms. While the vendor's CVE footprint is modest in volume relative to larger platforms, its presence in the vulnerability landscape reflects the product's enduring deployment in legacy and specialized web environments. Defenders managing Mambo installations should prioritize inventory and lifecycle assessment, particularly for aging deployments; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
149
Total CVEs
More Total CVEs than 97% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mambo Foundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 25, 2001
24 years ago
Most Recent CVE
Feb 12, 2020
2,354 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (149 CVEs).

149 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-5362MEDIUM
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute
Oct 11, 20076.850NOYES
CVE-2008-2905MEDIUM
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote atta
Jun 30, 20086.843NOYES
CVE-2007-1699HIGH
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary
Mar 27, 200710.043NOYES
CVE-2003-1245HIGH
index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie.
Dec 31, 200310.042NOYES
CVE-2007-2005MEDIUM
Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosCo
Apr 12, 20076.836NOYES
CVE-2007-1596HIGH
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP
Mar 22, 20079.336NOYES
CVE-2008-1465HIGH
SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id pa
Mar 24, 20089.335NOYES
CVE-2006-4296HIGH
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers to include arbitrary files via the mosCon
Aug 23, 20067.535NOYES
CVE-2011-2917HIGH
SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the zorder parameter.
Dec 8, 20117.534NOYES
CVE-2008-0772HIGH
SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view ta
Feb 14, 20087.533NOYES
View all 149 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products149 CVEs
33%
64%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (2.0%)
Unknown146 (98.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (2.0%)
High0 (0.0%)
Unknown146 (98.0%)
User Interaction
None2 (1.3%)
Unknown146 (98.0%)
Required1 (0.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (2.0%)
Unknown146 (98.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (149 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.7% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
104 CVEs
69.8% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mambo Foundation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mambo Foundation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mambo Foundation's Products

View all 3 CNAs →

Top CWEs