Product
mjdm majordomo
15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-27181
CVE-2026-27180
CVE-2026-27179
CVE-2026-27178
CVE-2026-27177
CVE-2026-27176
CVE-2026-27175
CVE-2026-27174
CVE-2023-50917
CVE-2010-0345
CVE-2003-1367
CVE-2000-0037
CVE-2000-0035
CVE-1999-1220
CVE-1999-0207
all versions
MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. The market
all versions
MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via u
all versions
MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module. The commands
all versions
MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability through method parameter injectio
all versions
MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability via the /objects/?op=set endpoint
all versions
MajorDoMo (aka Major Domestic Module) contains a reflected cross-site scripting (XSS) vulnerability in command.php. The $qry param
all versions
MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable
all versions
MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An i
< 2023-11-15
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is un
<= 1.1.3
Cross-site scripting (XSS) vulnerability in the Majordomo extension 1.1.3 and earlier for TYPO3 allows remote attackers to inject
<= 2.0
The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allo
all versions
Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.
<= 1.94.4
resend command in Majordomo allows local users to gain privileges via shell metacharacters.
<= 1.94.3
Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is
all versions
Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.