Neocrome maintains a modestly sized but prominent portfolio centered on web-based content-management and community platforms, particularly Land Down Under and Seditio, which serve as the vehicle for its disclosed vulnerabilities. The exposure recurs consistently through application-layer input-handling weaknesses—SQL injection, cross-site scripting, and sensitive-information disclosure—that are characteristic of web frameworks handling user-generated content and database queries. Public exploit code has frequently materialized for vulnerabilities in this vendor's products, reflecting both their accessibility as web applications and the straightforward nature of the underlying flaws. Defenders deploying these platforms should prioritize input validation and output-encoding hardening, particularly where user data flows to database queries or page generation; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Neocrome over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1411HIGH SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to p | Apr 24, 2009 | 7.5 | 30 | NO | YES |
CVE-2006-6177HIGH SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via | Nov 30, 2006 | 7.5 | 28 | NO | YES |
CVE-2005-4821HIGH Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m paramet | Dec 31, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-2788HIGH Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitrary SQL commands via the c parameter to (1) events.php, (2) | Sep 2, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-2675HIGH Note: the vendor has disputed this issue. Multiple SQL injection vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to execute arbitrary SQL commands via the (1) s | Aug 23, 2005 | 7.5 | 28 | NO | YES |
CVE-2007-6202MEDIUM SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] paramet | Dec 1, 2007 | 6.8 | 27 | NO | YES |
CVE-2007-4057MEDIUM Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote authenticated users to upload arbitrary PHP code via a filename ending with (1) | Jul 30, 2007 | 6.5 | 26 | NO | YES |
CVE-2006-6577MEDIUM SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | Dec 15, 2006 | 6.8 | 26 | NO | YES |
CVE-2006-6343MEDIUM SQL injection vulnerability in polls.php in Neocrome Seditio 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | Dec 7, 2006 | 6.8 | 26 | NO | YES |
CVE-2006-6268HIGH SQL injection vulnerability in system/core/profile/profile.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote authenticated users to execute arbitrary SQL comm | Dec 4, 2006 | 10.0 | 25 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Neocrome.
Media articles that mention a CVE ID that affects a product developed by Neocrome — matched by CVE ID, not by vendor name.