Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xoops CRITICAL 9.0
CVE-2023-36217

Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image …

No fix yet
Fix from $2,300 2023-08-03
Xoops MEDIUM 6.1
CVE-2017-12138

XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.

Mitigation only
Fix from $1,600 2017-08-02
Xoops MEDIUM 6.1
CVE-2017-12139

XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.

Mitigation only
Fix from $1,600 2017-08-02
Xoops CRITICAL 9.8
CVE-2017-11174

In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection…

Mitigation only
Fix from $2,300 2017-07-12
Xoops MEDIUM 6.1
CVE-2017-7944

XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php.

Mitigation only
Fix from $1,600 2017-04-24
Xoops HIGH 7.2
CVE-2017-7290

SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL co…

Patch available
Fix from $1,950 2017-03-30
Xoops MEDIUM 6.5
CVE-2014-8999

SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated users to execute arbitrary SQL…

Fix: after 2.5.6
Fix from $1,600 2014-11-20
Glossaire Module HIGH 7.5
CVE-2014-3935

SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via …

No fix yet
Fix from $1,950 2014-06-02
Xoops MEDIUM 5.0
CVE-2011-3822

XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an er…

Mitigation only
Fix from $1,600 2011-09-24
Xoops MEDIUM 5.0
CVE-2009-4851

The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, whic…

Fix: after 2.4.0
Fix from $1,600 2010-05-07
Xoops Dictionary HIGH 7.5
CVE-2009-4582

SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL commands via the…

No fix yet
Fix from $1,950 2010-01-06
Xoops HIGH 7.5
CVE-2009-3963

Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.

Fix: after 2.3.3
Fix from $1,950 2009-11-17
Uploader HIGH 7.5
CVE-2008-7178

Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename…

No fix yet
Fix from $1,950 2009-09-08
Xoops MEDIUM 6.8
CVE-2008-6884EPSS 6%

Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrar…

Patch available
Fix from $1,600 2009-07-31
Xoops HIGH 7.5
CVE-2008-5665

SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no paramete…

No fix yet
Fix from $1,950 2008-12-19
Makale HIGH 7.5
CVE-2008-4653

SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrar…

No fix yet
Fix from $1,950 2008-10-22
Xoops HIGH 7.5
CVE-2008-3296EPSS 6%

Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files …

Mitigation only
Fix from $1,950 2008-07-25
Article Module HIGH 7.5
CVE-2008-2094

SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id param…

No fix yet
Fix from $1,950 2008-05-06
Tutoriais Module HIGH 7.5
CVE-2008-1351

SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL commands via the tid parameter to…

No fix yet
Fix from $1,950 2008-03-17
Xm Memberstats HIGH 7.5
CVE-2008-1065

Multiple SQL injection vulnerabilities in index.php in the XM-Memberstats (xmmemberstats) 2.0e module for XOOPS allow remote attackers to execute arb…

No fix yet
Fix from $1,950 2008-02-28
Prayer List Module HIGH 7.5
CVE-2008-0936

SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL comma…

No fix yet
Fix from $1,950 2008-02-25
Eempregos Module HIGH 7.5
CVE-2008-0874

SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid para…

No fix yet
Fix from $1,950 2008-02-21
Mytopics HIGH 7.5
CVE-2008-0847

SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary SQL commands via the articleid…

No fix yet
Fix from $1,950 2008-02-21
Xoops HIGH 7.5
CVE-2008-0612

Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files vi…

Patch available
Fix from $1,950 2008-02-06
Xoops MEDIUM 5.0
CVE-2008-0613

Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary web sites and conduct phishing …

Patch available
Fix from $1,600 2008-02-06
Xoopsgallery Module MEDIUM 6.8
CVE-2008-0138

PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows…

No fix yet
Fix from $1,600 2008-01-08
Xoops MEDIUM 5.0
CVE-2007-6675

The b_system_comments_show function in htdocs/modules/system/blocks/system_blocks.php in XOOPS before 2.0.18 does not check permissions, which allows…

Fix: after 2.0.17_1
Fix from $1,600 2008-01-08
Mylinks Module HIGH 7.5
CVE-2007-5978

SQL injection vulnerability in brokenlink.php in the mylinks module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid p…

Mitigation only
Fix from $1,950 2007-11-15
Xoops HIGH 7.5
CVE-2007-5188

Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files via unspeci…

Fix: after 2.0.17.1-rc1
Fix from $1,950 2007-10-03
Articles Module HIGH 7.5
CVE-2007-3311

SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands …

Fix: after 1.02
Fix from $1,950 2007-06-21