Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.0 CVE-2023-36217 Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image … Xoops No fix yet Fix from $2,3002023-08-03 MEDIUM 6.1 CVE-2017-12138 XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter. Xoops Mitigation only Fix from $1,6002017-08-02 MEDIUM 6.1 CVE-2017-12139 XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php. Xoops Mitigation only Fix from $1,6002017-08-02 CRITICAL 9.8 CVE-2017-11174 In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection… Xoops Mitigation only Fix from $2,3002017-07-12 MEDIUM 6.1 CVE-2017-7944 XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php. Xoops Mitigation only Fix from $1,6002017-04-24 HIGH 7.2 CVE-2017-7290 SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL co… Xoops Patch available Fix from $1,9502017-03-30 MEDIUM 6.5 CVE-2014-8999 SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated users to execute arbitrary SQL… Xoops after 2.5.6 Fix from $1,6002014-11-20 HIGH 7.5 CVE-2014-3935 SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via … Glossaire Module No fix yet Fix from $1,9502014-06-02 MEDIUM 5.0 CVE-2011-3822 XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an er… Xoops Mitigation only Fix from $1,6002011-09-24 MEDIUM 5.0 CVE-2009-4851 The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, whic… Xoops after 2.4.0 Fix from $1,6002010-05-07 HIGH 7.5 CVE-2009-4582 SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL commands via the… Xoops Dictionary No fix yet Fix from $1,9502010-01-06 HIGH 7.5 CVE-2009-3963 Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors. Xoops after 2.3.3 Fix from $1,9502009-11-17 HIGH 7.5 CVE-2008-7178 Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename… Uploader No fix yet Fix from $1,9502009-09-08 MEDIUM 6.8 CVE-2008-6884EPSS 6% Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrar… Xoops Patch available Fix from $1,6002009-07-31 HIGH 7.5 CVE-2008-5665 SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no paramete… Xoops No fix yet Fix from $1,9502008-12-19 HIGH 7.5 CVE-2008-4653 SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrar… Makale No fix yet Fix from $1,9502008-10-22 HIGH 7.5 CVE-2008-3296EPSS 6% Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files … Xoops Mitigation only Fix from $1,9502008-07-25 HIGH 7.5 CVE-2008-2094 SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id param… Article Module No fix yet Fix from $1,9502008-05-06 HIGH 7.5 CVE-2008-1351 SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL commands via the tid parameter to… Tutoriais Module No fix yet Fix from $1,9502008-03-17 HIGH 7.5 CVE-2008-1065 Multiple SQL injection vulnerabilities in index.php in the XM-Memberstats (xmmemberstats) 2.0e module for XOOPS allow remote attackers to execute arb… Xm Memberstats No fix yet Fix from $1,9502008-02-28 HIGH 7.5 CVE-2008-0936 SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL comma… Prayer List Module No fix yet Fix from $1,9502008-02-25 HIGH 7.5 CVE-2008-0874 SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid para… Eempregos Module No fix yet Fix from $1,9502008-02-21 HIGH 7.5 CVE-2008-0847 SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary SQL commands via the articleid… Mytopics No fix yet Fix from $1,9502008-02-21 HIGH 7.5 CVE-2008-0612 Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files vi… Xoops Patch available Fix from $1,9502008-02-06 MEDIUM 5.0 CVE-2008-0613 Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary web sites and conduct phishing … Xoops Patch available Fix from $1,6002008-02-06 MEDIUM 6.8 CVE-2008-0138 PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows… Xoopsgallery Module No fix yet Fix from $1,6002008-01-08 MEDIUM 5.0 CVE-2007-6675 The b_system_comments_show function in htdocs/modules/system/blocks/system_blocks.php in XOOPS before 2.0.18 does not check permissions, which allows… Xoops after 2.0.17_1 Fix from $1,6002008-01-08 HIGH 7.5 CVE-2007-5978 SQL injection vulnerability in brokenlink.php in the mylinks module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid p… Mylinks Module Mitigation only Fix from $1,9502007-11-15 HIGH 7.5 CVE-2007-5188 Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files via unspeci… Xoops after 2.0.17.1-rc1 Fix from $1,9502007-10-03 HIGH 7.5 CVE-2007-3311 SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands … Articles Module after 1.02 Fix from $1,9502007-06-21