extrosoft CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

extrosoft vulnerability overview

Aggregates CVE and security vulnerability intelligence across all extrosoft-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk sql injection, vendor risk cross-site scripting, and vendor risk path handling; exposure may include vendor impact session compromise in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2008-6404 Cross-site scripting (XSS) vulnerability in add_calendars.php in eXtrovert Software Thyme 1.3 allows remote attackers to inject arbitrary web script or HTML via the callback parameter. [email protected] 4.3 0.26% 2009-03-06 2026-04-23
CVE-2009-0535 Directory traversal vulnerability in export.php in Thyme 1.3 and earlier, when register_globals is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the export_to parameter. [email protected] 7.5 2.90% 2009-02-11 2026-04-23
CVE-2008-6116 SQL injection vulnerability in the EXtrovert Software Thyme (com_thyme) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event parameter to index.php. [email protected] 7.5 0.60% 2009-02-11 2026-04-23
CVE-2006-2117 Cross-site scripting (XSS) vulnerability in Thyme 1.3 allows remote attackers to inject arbitrary web script or HTML via the search page. [email protected] 4.3 0.56% 2006-05-01 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence