Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mozilo

First CVE: Aug 11, 2008Active for: 18 yearsTotal CVEs: 17
34.5
VTI Score
Medium

Mozilo maintains a modestly represented portfolio of content-management and wiki systems that, despite narrow product scope, occupy a notable position in the vulnerability landscape. Its disclosures cluster around application-layer weaknesses—cross-site scripting, path traversal, improper authentication, unrestricted file uploads, and input-validation flaws—that are characteristic of web-facing CMS platforms, and the vendor's vulnerabilities have an elevated tendency to acquire public exploit tooling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mozilo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 11, 2008
17 years ago
Most Recent CVE
Sep 10, 2024
682 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-44871HIGH
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.
Sep 10, 20247.239NOYES
CVE-2022-23357CRITICAL
mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.
Feb 3, 20229.139NONO
CVE-2009-1368HIGH
Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. NOTE: this might be the
Apr 22, 20097.530NOYES
CVE-2008-6126MEDIUM
Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to download
Feb 13, 20095.025NOYES
CVE-2009-1369MEDIUM
moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter to index.php, or (4) file[] pa
Apr 22, 20095.023NOYES
CVE-2008-6128MEDIUM
Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
Feb 13, 20096.823NONO
CVE-2009-4209MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) fil
Dec 4, 20094.321NOYES
CVE-2009-1367MEDIUM
Cross-site scripting (XSS) vulnerability in index.php in moziloCMS 1.11 allows remote attackers to inject arbitrary web script or HTML via the query parameter in search action, a d
Apr 22, 20094.321NOYES
CVE-2008-3589MEDIUM
Directory traversal vulnerability in download.php in moziloCMS 1.10.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the
Aug 11, 20084.321NOYES
CVE-2024-44872MEDIUM
A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload
Sep 10, 20246.119NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
82%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (35.3%)
Unknown11 (64.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (35.3%)
High0 (0.0%)
Unknown11 (64.7%)
User Interaction
None3 (17.6%)
Unknown11 (64.7%)
Required3 (17.6%)
Privileges Required
Low1 (5.9%)
High2 (11.8%)
None3 (17.6%)
Unknown11 (64.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
41.2% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mozilo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mozilo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mozilo's Products

View all 2 CNAs →

Top CWEs