Rumpus
Vendor:
First CVE: Aug 25, 2009 · Active for 16 years
21
Total CVEs
More Total CVEs than 94% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rumpus over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2009
16 years ago
Most Recent CVE
Nov 17, 2025
250 days ago
CVE Severity & Scoring
Rumpus21 CVEs
52%
38%
10%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (95.2%)
Unknown1 (4.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (95.2%)
High0 (0.0%)
Unknown1 (4.8%)
User Interaction
None5 (23.8%)
Unknown1 (4.8%)
Required15 (71.4%)
Privileges Required
Low4 (19.0%)
High0 (0.0%)
None16 (76.2%)
Unknown1 (4.8%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19368MEDIUM A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can | Dec 16, 2019 | 6.1 | 50 | NO | YES |
CVE-2008-7078HIGH Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation fault) via a long HTTP verb in the HTTP component; and allow | Aug 25, 2009 | 9.0 | 35 | NO | YES |
CVE-2025-55058CRITICAL CWE-20 Improper Input Validation | Nov 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-55055CRITICAL CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | Nov 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2020-27575HIGH Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrators are able to manage users. The | Mar 8, 2021 | 8.8 | 30 | NO | NO |
CVE-2020-27574HIGH Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malicious page, unintended actions could be performed in the web | Mar 8, 2021 | 8.8 | 29 | NO | NO |
CVE-2022-46368HIGH Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users. | Jan 12, 2023 | 8.8 | 28 | NO | NO |
CVE-2022-46367HIGH Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation. | Jan 12, 2023 | 8.8 | 28 | NO | NO |
CVE-2025-55057HIGH Multiple CWE-352 Cross-Site Request Forgery (CSRF) | Nov 17, 2025 | 8.8 | 27 | NO | NO |
CVE-2019-19659HIGH A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changi | Feb 10, 2020 | 8.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.8% of CVEs· 97th percentile
ExploitDB
2 CVEs
9.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Rumpus
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.12 | 5 | 8.1 | 0.3% | 0 | 0 |
| 8.2.9.1 | 5 | 6.9 | 4.6% | 0 | 1 |
| 8.2.14 | 3 | 7.7 | 1.5% | 0 | 0 |
| 8.2.13 | 3 | 7.7 | 1.5% | 0 | 0 |
| 8.2.10 | 1 | 6.1 | 0.8% | 0 | 0 |