Mojoportal is a modestly represented open-source content management and portal framework whose vulnerabilities concentrate in the single core product and skew toward serious severity outcomes. The exposure recurs through web-application layer weakness classes including cross-site scripting, unrestricted file uploads, improper access control, and path traversal—characteristic flaws in user-facing CMS platforms—and frequently acquires public exploit code. Defenders deploying this framework should prioritize input-handling and access-control advisories; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mojoportal over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24322MEDIUM A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted | Feb 9, 2023 | 6.1 | 49 | NO | YES |
CVE-2025-28367MEDIUM mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web. | Apr 21, 2025 | 6.5 | 34 | NO | YES |
CVE-2023-44012MEDIUM Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component. | Oct 2, 2023 | 6.1 | 27 | NO | YES |
CVE-2023-24323HIGH Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability. | Feb 9, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-44009CRITICAL File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function. | Oct 2, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-44008CRITICAL File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function. | Oct 2, 2023 | 9.8 | 26 | NO | NO |
CVE-2022-40123MEDIUM mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to | Oct 3, 2022 | 6.5 | 25 | NO | NO |
CVE-2022-40341HIGH mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file. | Sep 30, 2022 | 8.8 | 25 | NO | NO |
CVE-2023-44011CRITICAL An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component. | Oct 2, 2023 | 9.8 | 24 | NO | NO |
CVE-2023-24687MEDIUM Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component. This vulnerability allows attackers to execu | Feb 9, 2023 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mojoportal.
Media articles that mention a CVE ID that affects a product developed by Mojoportal — matched by CVE ID, not by vendor name.