Vulnerability index

Browse CVEs

42 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Xoops CRITICAL 9.0
CVE-2023-36217

Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image …

No fix yet
Fix from $2,300 2023-08-03
Xoops MEDIUM 6.1
CVE-2017-12138

XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.

Mitigation only
Fix from $1,600 2017-08-02
Xoops MEDIUM 6.1
CVE-2017-12139

XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.

Mitigation only
Fix from $1,600 2017-08-02
Xoops CRITICAL 9.8
CVE-2017-11174

In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection…

Mitigation only
Fix from $2,300 2017-07-12
Xoops MEDIUM 6.1
CVE-2017-7944

XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php.

Mitigation only
Fix from $1,600 2017-04-24
Glossaire Module HIGH 7.5
CVE-2014-3935

SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via …

No fix yet
Fix from $1,950 2014-06-02
Xoops MEDIUM 5.0
CVE-2011-3822

XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an er…

Mitigation only
Fix from $1,600 2011-09-24
Xoops Dictionary HIGH 7.5
CVE-2009-4582

SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL commands via the…

No fix yet
Fix from $1,950 2010-01-06
Uploader HIGH 7.5
CVE-2008-7178

Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename…

No fix yet
Fix from $1,950 2009-09-08
Xoops HIGH 7.5
CVE-2008-5665

SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no paramete…

No fix yet
Fix from $1,950 2008-12-19
Makale HIGH 7.5
CVE-2008-4653

SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrar…

No fix yet
Fix from $1,950 2008-10-22
Xoops HIGH 7.5
CVE-2008-3296EPSS 6%

Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files …

Mitigation only
Fix from $1,950 2008-07-25
Article Module HIGH 7.5
CVE-2008-2094

SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id param…

No fix yet
Fix from $1,950 2008-05-06
Tutoriais Module HIGH 7.5
CVE-2008-1351

SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL commands via the tid parameter to…

No fix yet
Fix from $1,950 2008-03-17
Xm Memberstats HIGH 7.5
CVE-2008-1065

Multiple SQL injection vulnerabilities in index.php in the XM-Memberstats (xmmemberstats) 2.0e module for XOOPS allow remote attackers to execute arb…

No fix yet
Fix from $1,950 2008-02-28
Prayer List Module HIGH 7.5
CVE-2008-0936

SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL comma…

No fix yet
Fix from $1,950 2008-02-25
Eempregos Module HIGH 7.5
CVE-2008-0874

SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid para…

No fix yet
Fix from $1,950 2008-02-21
Mytopics HIGH 7.5
CVE-2008-0847

SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary SQL commands via the articleid…

No fix yet
Fix from $1,950 2008-02-21
Xoopsgallery Module MEDIUM 6.8
CVE-2008-0138

PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows…

No fix yet
Fix from $1,600 2008-01-08
Mylinks Module HIGH 7.5
CVE-2007-5978

SQL injection vulnerability in brokenlink.php in the mylinks module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid p…

Mitigation only
Fix from $1,950 2007-11-15
Wiwimod Module HIGH 7.5
CVE-2007-3289EPSS 12%

PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitra…

No fix yet
Fix from $1,950 2007-06-20
Horoscope Module HIGH 7.5
CVE-2007-3236EPSS 77%

PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via…

No fix yet
Fix from $1,950 2007-06-15
Tinycontent Module MEDIUM 6.8
CVE-2007-3237EPSS 68%

PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execu…

No fix yet
Fix from $1,600 2007-06-15
Xfsection Module HIGH 7.5
CVE-2007-3222EPSS 7%

PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code vi…

No fix yet
Fix from $1,950 2007-06-14
Cjay Content Module MEDIUM 6.8
CVE-2007-3220EPSS 63%

PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to exe…

No fix yet
Fix from $1,600 2007-06-14
Xt Conteudo Module MEDIUM 6.8
CVE-2007-3221EPSS 68%

PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute a…

No fix yet
Fix from $1,600 2007-06-14
Icontent Module MEDIUM 6.8
CVE-2007-3057EPSS 69%

PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to exe…

No fix yet
Fix from $1,600 2007-06-06
Myconference Module HIGH 7.5
CVE-2007-2737

SQL injection vulnerability in index.php in the MyConference 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the c…

Mitigation only
Fix from $1,950 2007-05-17
Flashgames Module HIGH 7.5
CVE-2007-2543

SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the li…

No fix yet
Fix from $1,950 2007-05-09
Rha7 Downloads Module HIGH 7.5
CVE-2007-1960

SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other versions up to 1.10, allows r…

No fix yet
Fix from $1,950 2007-04-11