← Back

Xoops

xoops

87 CVEs • 43 products

Products (43)

Click to collapse
Toggle
Xoops
xoops
Wf Downloads
wf-downloads
Core Module
core_module
Library Module
library_module
Wf Snippets
wf-snippets
Wiwimod Module
wiwimod_module
Mylinks Module
mylinks_module
Mytopics
mytopics
Xoops Cube
xoops_cube
Article Module
article_module
Kshop Module
kshop_module
Makale
makale
Uploader
uploader

CVEs (87)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xoops
1Xoops
Nov 21, 2024
Aug 3, 2023
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.
1Xoops
1Xoops
Nov 21, 2024
Sep 30, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is hovered over in the list or in the Edit page, the payload executes.
1Xoops
1Xoops
Nov 21, 2024
Sep 30, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered over while editing any image, a JavaScript payload executes.
1Xoops
1Xoops
May 13, 2026
Aug 2, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.
1Xoops
1Xoops
May 13, 2026
Aug 2, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.
1Xoops
1Xoops
May 13, 2026
Jul 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of GBK in CHARACTER SET...Show more
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of GBK in CHARACTER SET and COLLATE clauses.Show less
1Xoops
1Xoops
May 13, 2026
Apr 24, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php.
1Xoops
1Xoops
May 13, 2026
Mar 30, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "...Show more
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.Show less
1Xoops
1Xoops
May 6, 2026
Nov 20, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated users to execute arbitrary SQL commands via the selgroups parameter.
1Xoops
1Xoops
May 6, 2026
Sep 11, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) to_userid parameter to modules/pm/pmlite.php or the (2) current_file, (3...Show more
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) to_userid parameter to modules/pm/pmlite.php or the (2) current_file, (3) imgcat_id, or (4) target parameter to class/xoopseditor/tinymce/tinymce/jscripts/tiny_mce/plugins/xoopsimagemanager/xoopsimagebrowser.php.Show less
1Xoops
1Glossaire Module
May 6, 2026
Jun 2, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via the lettre parameter.
1Xoops
1Xoops
Apr 29, 2026
Nov 28, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to include/formdhtmltextarea_p...Show more
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to include/formdhtmltextarea_preview.php or (2) img BBCODE tag within the message parameter to pmlite.php (aka Private Message). NOTE: some of these details are obtained from third party information.Show less
1Xoops
1Xoops
Apr 29, 2026
Sep 24, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/system/xoops_version.php and ce...Show more
XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/system/xoops_version.php and certain other files.Show less
1Xoops
1Xoops
Apr 29, 2026
May 7, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a reque...Show more
The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php.Show less
1Xoops
1Xoops Dictionary
Apr 23, 2026
Jan 6, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Xoops
1Xoops
Apr 23, 2026
Nov 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.
1Xoops
1Uploader
Apr 23, 2026
Sep 8, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a downloadfile action to index.php.
1Xoops
1Xoops
Apr 23, 2026
Aug 17, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parameter to modules/pm/viewpmsg.php and (2) query string to modules/profile...Show more
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parameter to modules/pm/viewpmsg.php and (2) query string to modules/profile/user.php.Show less
1Xoops
1Xoops
Apr 23, 2026
Jul 31, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in pmlite.php in XOOPS 2.3.1 and 2.3.2a allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute in a URL BBcode tag in a private message.
1Xoops
1Xoops
Apr 23, 2026
Jul 31, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter...Show more
Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter to (1) blocks.php and (2) main.php in xoops_lib/modules/protector/.Show less