Mvnforum is a web-based forum application where the durable signal concentrates on client-side and request-validation weaknesses, particularly cross-site scripting and cross-site request forgery flaws typical of server-rendered web applications. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mvnforum over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1183MEDIUM Cross-site scripting (XSS) vulnerability in mvnForum 1.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the Search parameter. | May 2, 2005 | 4.3 | 21 | NO | YES |
CVE-2008-5400MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in mvnForum before 1.2.1 GA allow remote attackers to (1) create forums, (2) change account privileges, (3) enable accoun | Dec 10, 2008 | 6.8 | 19 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in activatemember in mvnForum 1.0 GA and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) membe | Jun 27, 2006 | 2.6 | 18 | NO | YES |
CVE-2008-5399MEDIUM Cross-site scripting (XSS) vulnerability in the listonlineusers (aka "Who's online") component in mvnForum before 1.2.1 GA allows remote attackers to inject arbitrary web script or | Dec 10, 2008 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mvnforum.
Media articles that mention a CVE ID that affects a product developed by Mvnforum — matched by CVE ID, not by vendor name.