Userland's vulnerability profile is limited to its Manila content-management and file-sharing product, a focused portfolio with observed weaknesses centered on miscellaneous implementation issues rather than a clear dominant flaw class. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Userland over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1769MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila 9.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the mode parameter in m | Apr 13, 2006 | 6.8 | 18 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila allow remote attackers to inject arbitrary web script or HTML (1) via the referer parameter in sendMail, and | Apr 20, 2006 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Userland.
Media articles that mention a CVE ID that affects a product developed by Userland — matched by CVE ID, not by vendor name.