Nooms maintains a focused product offering centered on its primary application, where observed vulnerabilities cluster around information-disclosure risks, path-traversal conditions, and web-application input-handling flaws including cross-site scripting. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nooms over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4179MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) page_id parameter to smileys.php and the | Sep 23, 2008 | 4.3 | 21 | NO | YES |
CVE-2008-4180MEDIUM Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbuser parameter and a password in | Sep 23, 2008 | 5.0 | 16 | NO | NO |
CVE-2008-4162MEDIUM Open redirect vulnerability in admin/auth.php in NooMS 1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the g_site_url | Sep 22, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nooms.
Media articles that mention a CVE ID that affects a product developed by Nooms — matched by CVE ID, not by vendor name.