Moxiecode maintains a narrow portfolio of web-facing utilities—notably the Plupload file-upload component and TinyMCE Compressor—that are embedded in content management and publishing platforms. The recurring vulnerability signal centers on path-traversal and cross-site scripting flaws endemic to file-handling and script-injection surfaces in web middleware. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Moxiecode over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4600MEDIUM Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%0 | Dec 31, 2005 | 6.4 | 29 | NO | YES |
CVE-2012-2401MEDIUM Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was l | Apr 21, 2012 | 5.0 | 19 | NO | NO |
CVE-2013-0237MEDIUM Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject | Jul 8, 2013 | 4.3 | 16 | NO | NO |
CVE-2005-4599MEDIUM Cross-site scripting (XSS) vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to inject arbitrary web script or HTML via the index par | Dec 31, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Moxiecode.
Media articles that mention a CVE ID that affects a product developed by Moxiecode — matched by CVE ID, not by vendor name.