Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
xoops xoops 2.3.3 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2009-2783
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote malicious users to inject arbitrary web script or HTML via the (1) op parameter to modules/pm/viewpmsg.php and (2) query string to modules/profile/user.php.
Xoops Xoops 2.3.3
1 EDB exploit
NA
CVE-2011-4565
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote malicious users to inject arbitrary web script or HTML via the (1) text parameter to include/formdhtmltextarea_preview.php or (2) img BBCODE tag within the message pa...
Xoops Xoops 2.3.2b
Xoops Xoops 2.4.2
Xoops Xoops 2.0.2
Xoops Xoops 2.0.14
Xoops Xoops 2.0.16
Xoops Xoops 2.0.18.1
Xoops Xoops 2.0.15
Xoops Xoops 2.3.2a
Xoops Xoops 2.0.17.1
Xoops Xoops 2.0.18
Xoops Xoops 2.5.0
Xoops Xoops 2.0.18.2
Xoops Xoops 2.4.0
Xoops Xoops 2.0.13.2
Xoops Xoops 2.3.3b
Xoops Xoops 2.4.1
Xoops Xoops 2.4.4
Xoops Xoops 2.3.0
Xoops Xoops 2.4.3
Xoops Xoops
Xoops Xoops 2.0.17
Xoops Xoops 2.5.1
NA
CVE-2009-4851
The activation resend function in the Profiles module in XOOPS prior to 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote malicious users to bypass administrative approval via a request involving activate.php.
Xoops Xoops 2.3.0 Rc3
Xoops Xoops 1.3.6
Xoops Xoops 2.3.0 Rc
Xoops Xoops 2.3.2b
Xoops Xoops 2.0.12
Xoops Xoops 2.3.0 Alpha 3
Xoops Xoops 2.0.5.1
Xoops Xoops 2.0.2
Xoops Xoops 2.0.12a
Xoops Xoops 2.0.5.2
Xoops Xoops 2.0.16
Xoops Xoops 2.3.0 Beta
Xoops Xoops 2.0.0 Rc1
Xoops Xoops 2.0.13.1
Xoops Xoops 2.0.0 Rc2
Xoops Xoops 2.0.7.3
Xoops Xoops 1.3.10
Xoops Xoops 2.0.15
Xoops Xoops 2.0.13
Xoops Xoops 2.3.2a
Xoops Xoops 2.4.0 Beta 1
Xoops Xoops 1.3.5
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-30078
CVE-2024-37896
code injection
CVE-2024-3080
CVE-2024-5172
cross-site request forgery
CVE-2024-6111
firmware
CVE-2024-38504
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started