Mjdm's vulnerability footprint centers on Majordomo, a widely deployed mailing-list management system whose email and web interfaces handle user input and command generation. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by recurring input-handling and code-injection weakness classes including cross-site scripting, command injection, OS command injection, and unsafe code generation that are characteristic of legacy mail-handling software. Defenders should treat disclosed vulnerabilities in this vendor as high-priority given the severity and exploit tendency; live exploitation status and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mjdm over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50917CRITICAL MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager. | Dec 15, 2023 | 9.8 | 70 | NO | YES |
CVE-2026-27174CRITICAL MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in modules/panel.class.php causes | Feb 18, 2026 | 9.8 | 62 | NO | YES |
CVE-2026-27175CRITICAL MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is interpolated into a command str | Feb 18, 2026 | 9.8 | 50 | NO | YES |
CVE-2026-27180CRITICAL MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via update URL poisoning. The saverestore module expose | Feb 18, 2026 | 9.8 | 46 | NO | YES |
CVE-2026-27179CRITICAL MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module. The commands_search.inc.php file directly interpolates the $_G | Feb 18, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-27176MEDIUM MajorDoMo (aka Major Domestic Module) contains a reflected cross-site scripting (XSS) vulnerability in command.php. The $qry parameter is rendered directly into the HTML page witho | Feb 18, 2026 | 6.1 | 32 | NO | YES |
CVE-2026-27181HIGH MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. The market module's admin() method reads gr('mode') from $_R | Feb 18, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-27178MEDIUM MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability through method parameter injection into the shoutbox. The /objects/?method= endpoin | Feb 18, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-27177MEDIUM MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability via the /objects/?op=set endpoint, which is intentionally unauthenticated for IoT d | Feb 18, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mjdm.
Media articles that mention a CVE ID that affects a product developed by Mjdm — matched by CVE ID, not by vendor name.