Mxmania develops a focused portfolio of web-based productivity and content-management tools, including calendar, gallery, file-upload, and newsletter products that are typically deployed in small-to-medium business environments. The vendor's vulnerability profile centers on application-layer input-handling weaknesses, particularly SQL injection, that are characteristic of web application backends, and its disclosures frequently acquire public exploit tooling. Live severity, exploitation activity, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mxmania over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6379HIGH SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | Mar 2, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6378HIGH SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | Mar 2, 2009 | 7.5 | 28 | NO | YES |
CVE-2006-6813HIGH SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. | Dec 29, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6787HIGH SQL injection vulnerability in admin/admin_mail_adressee.asp in Newsletter MX 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. | Dec 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6792HIGH SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: The | Dec 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6825HIGH Calendar MX BASIC 1.0.2 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a dire | Dec 29, 2006 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mxmania.
Media articles that mention a CVE ID that affects a product developed by Mxmania — matched by CVE ID, not by vendor name.