Mangoswebv4 Project maintains a narrowly scoped web framework product that serves as the web layer for a specialized application domain, with vulnerabilities concentrating in cross-site scripting weaknesses characteristic of web-facing input-handling challenges. The durable signal is the recurrence of improper input neutralization issues in this web framework, while public exploit tooling has been developed for vulnerabilities in this product class. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mangoswebv4 Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6478MEDIUM paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter). | Mar 5, 2017 | 6.1 | 41 | NO | YES |
CVE-2017-6810MEDIUM paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.fplinks.php (linkid parameter). | Mar 11, 2017 | 6.1 | 22 | NO | NO |
CVE-2017-6809MEDIUM paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.donate.php (id parameter). | Mar 11, 2017 | 6.1 | 22 | NO | NO |
CVE-2017-6812MEDIUM paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.vote.php (id parameter). | Mar 11, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-6811MEDIUM paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.shop.php (id parameter). | Mar 11, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-6808MEDIUM paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.faq.php (id parameter). | Mar 11, 2017 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mangoswebv4 Project.
Media articles that mention a CVE ID that affects a product developed by Mangoswebv4 Project — matched by CVE ID, not by vendor name.