Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Maxum

First CVE: Aug 25, 2009Active for: 17 yearsTotal CVEs: 29
33.6
VTI Score
Medium

Maxum maintains a narrowly focused product line centered on the Rumpus family of FTP and file-transfer servers, which occupy a specialized but persistent niche in environments requiring legacy protocol support and managed file exchange. Despite the compact product portfolio, the vendor's vulnerabilities span multiple decades of disclosures and recur through application-layer input-handling weaknesses—including cross-site request forgery, cross-site scripting, OS command injection, improper input validation, and path-traversal flaws—that are characteristic of web-facing administrative interfaces layered atop system-level services. These weakness classes reflect the parsing and access-control challenges inherent to bridging user input from a web console to underlying file-system and process operations. A meaningful share of the vendor's disclosures reach serious severity, and public exploit code has surfaced for select vulnerabilities. Defenders operating legacy Rumpus instances should treat this vendor's advisories as a patching priority, particularly those affecting internet-reachable or multi-tenant deployments; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Maxum over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2009
16 years ago
Most Recent CVE
Nov 17, 2025
250 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-19368MEDIUM
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can
Dec 16, 20196.150NOYES
CVE-2008-7078HIGH
Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation fault) via a long HTTP verb in the HTTP component; and allow
Aug 25, 20099.035NOYES
CVE-2025-55058CRITICAL
CWE-20 Improper Input Validation
Nov 17, 20259.830NONO
CVE-2025-55055CRITICAL
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Nov 17, 20259.830NONO
CVE-2020-27575HIGH
Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrators are able to manage users. The
Mar 8, 20218.830NONO
CVE-2020-27574HIGH
Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malicious page, unintended actions could be performed in the web
Mar 8, 20218.829NONO
CVE-2022-46368HIGH
Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.
Jan 12, 20238.828NONO
CVE-2022-46367HIGH
Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation.
Jan 12, 20238.828NONO
CVE-2025-55057HIGH
Multiple CWE-352 Cross-Site Request Forgery (CSRF)
Nov 17, 20258.827NONO
CVE-2019-19659HIGH
A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changi
Feb 10, 20208.825NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
62%
31%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (96.6%)
Unknown1 (3.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (96.6%)
High0 (0.0%)
Unknown1 (3.4%)
User Interaction
None5 (17.2%)
Unknown1 (3.4%)
Required23 (79.3%)
Privileges Required
Low4 (13.8%)
High0 (0.0%)
None24 (82.8%)
Unknown1 (3.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.4% of CVEs· 95th percentile
ExploitDB
2 CVEs
6.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Maxum.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Maxum — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Maxum's Products

View all 2 CNAs →

Top CWEs