Mossle's vulnerability footprint centers on its Lemon product and clusters around web-application input handling, reflecting the intersection of user-supplied content and page rendering in interactive systems. The observed weakness classes—cross-site scripting, unrestricted file uploads, and improper access control—point to challenges in input validation and trust boundaries typical of web-facing applications.
The number and severity of CVEs published that impact products developed by Mossle over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9406CRITICAL A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the component com.mossle.cms.web.Cms | Aug 25, 2025 | 9.8 | 33 | NO | NO |
CVE-2018-18315HIGH com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFileToFile method in CdnUtils only checks for a ../ substring, | Oct 15, 2018 | 7.5 | 25 | NO | NO |
CVE-2020-20598MEDIUM A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML. | Dec 22, 2021 | 6.1 | 22 | NO | NO |
CVE-2020-20597MEDIUM A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML | Dec 22, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mossle.
Media articles that mention a CVE ID that affects a product developed by Mossle — matched by CVE ID, not by vendor name.