Mozilo maintains a modestly represented portfolio of content-management and wiki systems that, despite narrow product scope, occupy a notable position in the vulnerability landscape. Its disclosures cluster around application-layer weaknesses—cross-site scripting, path traversal, improper authentication, unrestricted file uploads, and input-validation flaws—that are characteristic of web-facing CMS platforms, and the vendor's vulnerabilities have an elevated tendency to acquire public exploit tooling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mozilo over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-44871HIGH An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file. | Sep 10, 2024 | 7.2 | 39 | NO | YES |
CVE-2022-23357CRITICAL mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir. | Feb 3, 2022 | 9.1 | 39 | NO | NO |
CVE-2009-1368HIGH Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. NOTE: this might be the | Apr 22, 2009 | 7.5 | 30 | NO | YES |
CVE-2008-6126MEDIUM Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to download | Feb 13, 2009 | 5.0 | 25 | NO | YES |
CVE-2009-1369MEDIUM moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter to index.php, or (4) file[] pa | Apr 22, 2009 | 5.0 | 23 | NO | YES |
CVE-2008-6128MEDIUM Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | Feb 13, 2009 | 6.8 | 23 | NO | NO |
CVE-2009-4209MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) fil | Dec 4, 2009 | 4.3 | 21 | NO | YES |
CVE-2009-1367MEDIUM Cross-site scripting (XSS) vulnerability in index.php in moziloCMS 1.11 allows remote attackers to inject arbitrary web script or HTML via the query parameter in search action, a d | Apr 22, 2009 | 4.3 | 21 | NO | YES |
CVE-2008-3589MEDIUM Directory traversal vulnerability in download.php in moziloCMS 1.10.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the | Aug 11, 2008 | 4.3 | 21 | NO | YES |
CVE-2024-44872MEDIUM A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload | Sep 10, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mozilo.
Media articles that mention a CVE ID that affects a product developed by Mozilo — matched by CVE ID, not by vendor name.