Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
xoops xoops vulnerabilities and exploits
(subscribe to this query)
9
CVSSv3
CVE-2023-36217
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote malicious user to execute arbitrary code via the category name field of the image manager function.
Xoops Xoops 2.5.10
4.8
CVSSv3
CVE-2019-16683
An issue exists in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered over while editing any image, a JavaScript payload executes.
Xoops Xoops 2.5.10
4.8
CVSSv3
CVE-2019-16684
An issue exists in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is hovered over in the list or in the Edit page, the payload executes.
Xoops Xoops 2.5.10
6.1
CVSSv3
CVE-2017-12138
XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.
Xoops Xoops 2.5.8
6.1
CVSSv3
CVE-2017-12139
XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.
Xoops Xoops 2.5.8
9.8
CVSSv3
CVE-2017-11174
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of GBK in CHARACTER SET and COLLATE clauses.
Xoops Xoops 2.5.8.1
6.1
CVSSv3
CVE-2017-7944
XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php.
Xoops Xoops 2.5.8.1
7.2
CVSSv3
CVE-2017-7290
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions prior to 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.
Xoops Xoops 2.5.8.1
Xoops Xoops 2.5.7.3
Xoops Xoops 2.5.7.2
NA
CVE-2014-8999
SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS prior to 2.5.7 Final allows remote authenticated users to execute arbitrary SQL commands via the selgroups parameter.
Xoops Xoops
NA
CVE-2012-0984
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS prior to 2.5.5 allow remote malicious users to inject arbitrary web script or HTML via the (1) to_userid parameter to modules/pm/pmlite.php or the (2) current_file, (3) imgcat_id, or (4) target parameter to class/xoopse...
Xoops Xoops 2.5.2
Xoops Xoops 2.5.3
Xoops Xoops
Xoops Xoops 2.5.0
Xoops Xoops 2.5.1
3 EDB exploits
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »