Skymoonlabs develops a narrow product line centered on file management and data migration applications such as Cleanto and Moveto, with a recurring vulnerability signal in application-layer input handling and file-upload controls. The durable exposure pattern reflects SQL injection and unrestricted file-upload weaknesses typical of web-facing administrative tools; live severity, exploitation, and volume details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Skymoonlabs over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-6295CRITICAL Cleanto 5.0 has SQL Injection via the assets/lib/service_method_ajax.php service_id parameter. | Jan 15, 2019 | 9.8 | 30 | NO | NO |
CVE-2024-25913CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. | Feb 26, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-25910CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. | Feb 28, 2024 | 9.8 | 25 | NO | NO |
CVE-2019-6296CRITICAL Cleanto 5.0 has SQL Injection via the assets/lib/export_ajax.php id parameter. | Jan 15, 2019 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Skymoonlabs.
Media articles that mention a CVE ID that affects a product developed by Skymoonlabs — matched by CVE ID, not by vendor name.