Nwom operates a narrowly scoped product line centered on its TopSites offering, which functions as a web-ranking or site-categorization service. The observed vulnerability disclosures center on miscellaneous implementation issues rather than a consistent structural weakness class, reflecting the diverse potential attack surfaces within web-ranking and categorization infrastructure. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nwom over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0249MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Nwom topsites 3.0 allows remote attackers to inject arbitrary web script or HTML via the o parameter. | Jan 16, 2007 | 6.8 | 18 | NO | NO |
CVE-2007-0250MEDIUM index.php in Nwom topsites 3.0 allows remote attackers to obtain potentially sensitive information via a ' (quote) character in the o parameter, which forces a SQL error. | Jan 16, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nwom.
Media articles that mention a CVE ID that affects a product developed by Nwom — matched by CVE ID, not by vendor name.