Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
xoops xoops 2.3.1 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2008-6885
Cross-site scripting (XSS) vulnerability in pmlite.php in XOOPS 2.3.1 and 2.3.2a allows remote malicious users to inject arbitrary web script or HTML via a STYLE attribute in a URL BBcode tag in a private message.
Xoops Xoops 2.3.1
Xoops Xoops 2.3.2a
6.8
CVSSv2
CVE-2008-6884
Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter to (1) blocks.php and (2) main.php in xoops_lib/modul...
Xoops Xoops 2.3.1
1 EDB exploit
4.3
CVSSv2
CVE-2011-4565
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote malicious users to inject arbitrary web script or HTML via the (1) text parameter to include/formdhtmltextarea_preview.php or (2) img BBCODE tag within the message pa...
Xoops Xoops 2.0.2
Xoops Xoops 2.5.0
Xoops Xoops 2.3.3b
Xoops Xoops 2.3.3
Xoops Xoops 2.0.18.1
Xoops Xoops 2.0.18
Xoops Xoops 2.0.14
Xoops Xoops
Xoops Xoops 2.5.1
Xoops Xoops 2.4.1
Xoops Xoops 2.4.0
Xoops Xoops 2.0.18.2
Xoops Xoops 2.0.17
Xoops Xoops 2.0.16
Xoops Xoops 2.0.15
Xoops Xoops 2.4.5
Xoops Xoops 2.4.4
Xoops Xoops 2.3.2b
Xoops Xoops 2.3.2a
Xoops Xoops 2.0.17.1
Xoops Xoops 2.0.13.2
Xoops Xoops 2.4.3
7.5
CVSSv2
CVE-2009-3963
Multiple unspecified vulnerabilities in XOOPS prior to 2.4.0 Final have unknown impact and attack vectors.
Xoops Xoops 2.0.13.2
Xoops Xoops 2.0.13.1
Xoops Xoops 2.0.4
Xoops Xoops 2.0.18.1
Xoops Xoops 2.0.18
Xoops Xoops 2.3.2a
Xoops Xoops 2.2.3
Xoops Xoops 2.0.17.1
Xoops Xoops 2.0.11
Xoops Xoops 2.0.12 Jp
Xoops Xoops 2.0.2
Xoops Xoops 2.0.6
Xoops Xoops 2.0.9.3
Xoops Xoops 2.0.9.2
Xoops Xoops 2.0.1
Xoops Xoops 2.0.10
Xoops Xoops 2.0.3
Xoops Xoops 2.0.17 1
Xoops Xoops 2.3.1
Xoops Xoops 2.0.7
Xoops Xoops 2.0.16
Xoops Xoops 2.0.14
5
CVSSv2
CVE-2009-4851
The activation resend function in the Profiles module in XOOPS prior to 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote malicious users to bypass administrative approval via a request involving activate.php.
Xoops Xoops 1.0
Xoops Xoops 1.0 Rc3
Xoops Xoops 1.3.10
Xoops Xoops 1.3.9
Xoops Xoops 2.0.0 Rc2
Xoops Xoops 2.0.5 Rc
Xoops Xoops 2.0.5.2
Xoops Xoops 2.0.9.2
Xoops Xoops 2.0.10 Rc
Xoops Xoops 2.0.13
Xoops Xoops 2.0.13.2
Xoops Xoops 2.0.18
Xoops Xoops 2.3.0 Alpha1
Xoops Xoops 2.3.0
Xoops Xoops 2.3.1
Xoops Xoops 2.4.0 Beta 2
Xoops Xoops
Xoops Xoops 1.3.5
Xoops Xoops 1.3.6
Xoops Xoops 1.3.7
Xoops Xoops 1.3.8
Xoops Xoops 2.0.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
HTML injection
CVE-2024-35894
SQL
CVE-2024-5105
CVE-2014-100005
CVE-2024-35895
unauthorized
CVE-2024-22120
CVE-2024-35890
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started