Montala maintains a resource-management platform, ResourceSpace, that sits in institutional and media-workflow environments and has an elevated tendency toward critical-severity outcomes across its disclosures. The vendor's exposure concentrates around application-layer input handling and request validation, with recurring weakness classes including SQL injection, path traversal, cross-site scripting, and cross-site request forgery, alongside improper input validation—defects typical of web applications with broad user input surfaces. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the accessibility and appeal of web-facing asset-management platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Montala over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41951MEDIUM ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php via the wordpress_user parameter. If an at | Nov 15, 2021 | 6.1 | 73 | NO | YES |
CVE-2021-41950CRITICAL A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider | Nov 15, 2021 | 9.1 | 68 | NO | NO |
CVE-2021-41765CRITICAL A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to execute arbitrary SQL commands | Nov 15, 2021 | 9.8 | 64 | NO | NO |
CVE-2015-3648HIGH Directory traversal vulnerability in pages/setup.php in Montala Limited ResourceSpace before 7.2.6727 allows remote attackers to include and execute arbitrary local files via a .. | Jun 9, 2015 | 7.5 | 31 | NO | YES |
CVE-2019-25662HIGH ResourceSpace 8.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'ref' param | Apr 5, 2026 | 8.2 | 27 | NO | NO |
CVE-2022-31260MEDIUM In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value. | Jul 17, 2022 | 6.5 | 26 | NO | YES |
CVE-2019-25693HIGH ResourceSpace 8.6 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keywords para | Apr 12, 2026 | 7.1 | 23 | NO | NO |
CVE-2015-6915HIGH SQL injection vulnerability in Montala Limited ResourceSpace 7.3.7009 and earlier allows remote attackers to execute arbitrary SQL commands via the "user" cookie to plugins/feedbac | Sep 11, 2015 | 7.5 | 20 | NO | NO |
CVE-2011-4311MEDIUM ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unspecified vectors. | Nov 19, 2011 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Montala.
Media articles that mention a CVE ID that affects a product developed by Montala — matched by CVE ID, not by vendor name.