Skip to content

Known CVE

mojoPortal <=2.9.0.1 - Directory Traversal

mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.

CVE-2025-28367

Medium2025CVSS 6.5CWE-284

cve2025 · mojoportal · lfi · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website