Vulnerability index

Browse CVEs

42 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.0 CVE-2023-36217 Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image … Xoops No fix yet Fix from $2,3002023-08-03 MEDIUM 6.1 CVE-2017-12138 XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter. Xoops Mitigation only Fix from $1,6002017-08-02 MEDIUM 6.1 CVE-2017-12139 XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php. Xoops Mitigation only Fix from $1,6002017-08-02 CRITICAL 9.8 CVE-2017-11174 In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection… Xoops Mitigation only Fix from $2,3002017-07-12 MEDIUM 6.1 CVE-2017-7944 XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php. Xoops Mitigation only Fix from $1,6002017-04-24 HIGH 7.5 CVE-2014-3935 SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via … Glossaire Module No fix yet Fix from $1,9502014-06-02 MEDIUM 5.0 CVE-2011-3822 XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an er… Xoops Mitigation only Fix from $1,6002011-09-24 HIGH 7.5 CVE-2009-4582 SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL commands via the… Xoops Dictionary No fix yet Fix from $1,9502010-01-06 HIGH 7.5 CVE-2008-7178 Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename… Uploader No fix yet Fix from $1,9502009-09-08 HIGH 7.5 CVE-2008-5665 SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no paramete… Xoops No fix yet Fix from $1,9502008-12-19 HIGH 7.5 CVE-2008-4653 SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrar… Makale No fix yet Fix from $1,9502008-10-22 HIGH 7.5 CVE-2008-3296EPSS 6% Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files … Xoops Mitigation only Fix from $1,9502008-07-25 HIGH 7.5 CVE-2008-2094 SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id param… Article Module No fix yet Fix from $1,9502008-05-06 HIGH 7.5 CVE-2008-1351 SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL commands via the tid parameter to… Tutoriais Module No fix yet Fix from $1,9502008-03-17 HIGH 7.5 CVE-2008-1065 Multiple SQL injection vulnerabilities in index.php in the XM-Memberstats (xmmemberstats) 2.0e module for XOOPS allow remote attackers to execute arb… Xm Memberstats No fix yet Fix from $1,9502008-02-28 HIGH 7.5 CVE-2008-0936 SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL comma… Prayer List Module No fix yet Fix from $1,9502008-02-25 HIGH 7.5 CVE-2008-0874 SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid para… Eempregos Module No fix yet Fix from $1,9502008-02-21 HIGH 7.5 CVE-2008-0847 SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary SQL commands via the articleid… Mytopics No fix yet Fix from $1,9502008-02-21 MEDIUM 6.8 CVE-2008-0138 PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows… Xoopsgallery Module No fix yet Fix from $1,6002008-01-08 HIGH 7.5 CVE-2007-5978 SQL injection vulnerability in brokenlink.php in the mylinks module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid p… Mylinks Module Mitigation only Fix from $1,9502007-11-15 HIGH 7.5 CVE-2007-3289EPSS 12% PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitra… Wiwimod Module No fix yet Fix from $1,9502007-06-20 HIGH 7.5 CVE-2007-3236EPSS 77% PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via… Horoscope Module No fix yet Fix from $1,9502007-06-15 MEDIUM 6.8 CVE-2007-3237EPSS 68% PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execu… Tinycontent Module No fix yet Fix from $1,6002007-06-15 HIGH 7.5 CVE-2007-3222EPSS 7% PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code vi… Xfsection Module No fix yet Fix from $1,9502007-06-14 MEDIUM 6.8 CVE-2007-3220EPSS 63% PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to exe… Cjay Content Module No fix yet Fix from $1,6002007-06-14 MEDIUM 6.8 CVE-2007-3221EPSS 68% PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute a… Xt Conteudo Module No fix yet Fix from $1,6002007-06-14 MEDIUM 6.8 CVE-2007-3057EPSS 69% PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to exe… Icontent Module No fix yet Fix from $1,6002007-06-06 HIGH 7.5 CVE-2007-2737 SQL injection vulnerability in index.php in the MyConference 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the c… Myconference Module Mitigation only Fix from $1,9502007-05-17 HIGH 7.5 CVE-2007-2543 SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the li… Flashgames Module No fix yet Fix from $1,9502007-05-09 HIGH 7.5 CVE-2007-1960 SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other versions up to 1.10, allows r… Rha7 Downloads Module No fix yet Fix from $1,9502007-04-11