Tomalofficial maintains a PHP-based object-oriented CMS and blogging platform with a modest vulnerability footprint centered on application-layer input-handling and state-management flaws. The recurring weakness classes—cross-site request forgery and SQL injection—reflect common risks in web applications where user input and session handling interact with database queries. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tomalofficial over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-25199CRITICAL OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through multiple parameter | Mar 6, 2026 | 9.8 | 31 | NO | NO |
CVE-2018-25200HIGH OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by crafting malicious POST request | Mar 6, 2026 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tomalofficial.
Media articles that mention a CVE ID that affects a product developed by Tomalofficial — matched by CVE ID, not by vendor name.