Realm Project's vulnerability footprint centers on Realm CMS, a web-based content management system where the durable signal reflects application-layer input-handling and data-exposure risks such as cross-site scripting, SQL injection, and improper information disclosure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Realm Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2682HIGH _RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUse | Jun 12, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-2679HIGH SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via th | Jun 12, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-2681MEDIUM Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.asp, which reveals the database path in an error message. | Jun 12, 2008 | 5.0 | 23 | NO | YES |
CVE-2008-2680MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in _db/compact.asp in Realm CMS 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Cmpcte | Jun 12, 2008 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Realm Project.
Media articles that mention a CVE ID that affects a product developed by Realm Project — matched by CVE ID, not by vendor name.