Cross Site Scripting (XSS) in xiunobbs 4.0.4 allows remote attackers to execute arbitrary web script or HTML via the attachment upload function.
A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts …
A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scr…
A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scr…
An issue in the component route\user.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames.
Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.
The editor in Xiuno BBS 4.0.4 allows stored XSS.