← Back

Xiuno

xiuno

7 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Xiunobbs
xiunobbs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xiuno
1Xiunobbs
Nov 21, 2024
Sep 7, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) in xiunobbs 4.0.4 allows remote attackers to execute arbitrary web script or HTML via the attachment upload function.
1Xiuno
1Xiunobbs
Nov 21, 2024
Oct 4, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitebrief parameter.
1Xiuno
1Xiunobbs
Nov 21, 2024
Oct 4, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitename parameter.
1Xiuno
1Xiunobbs
Nov 21, 2024
Oct 4, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via changing the doctype value to 0.
1Xiuno
1Xiunobbs
Nov 21, 2024
Oct 4, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue in the component route\user.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames.
1Xiuno
1Xiunobbs
Nov 21, 2024
Dec 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.
1Xiuno
1Xiunobbs
Nov 21, 2024
Aug 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The editor in Xiuno BBS 4.0.4 allows stored XSS.