CVE-2023-50917: Mjdm Majordomo

Critical severity, CVSS 9.8. EPSS: 38% chance of exploitation in the next 30 days.

MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.

Affected products

  • Mjdm Majordomo: before 2023-11-15 (fixed in 2023-11-15)

Published 2023-12-15. Last modified 2026-06-17.