CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2019-25433 HIGH

XOOPS CMS 2.5.9 SQL Injection via gerar_pdf.php

CVSS 8.8 EPSS 0.27% Feb 22, 2026
CVE-2023-36217 CRITICAL

Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager fu…

CVSS 9.0 EPSS 1.56% Aug 3, 2023
CVE-2019-16684 MEDIUM

An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is hovered over in the list or in the Edit p…

CVSS 4.8 EPSS 1.02% Sep 30, 2019
CVE-2019-16683 MEDIUM

An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered over while editing any image, a JavaScri…

CVSS 4.8 EPSS 1.02% Sep 30, 2019
CVE-2017-12139 MEDIUM

XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.

CVSS 6.1 EPSS 0.78% Aug 2, 2017
CVE-2017-12138 MEDIUM

XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.

CVSS 6.1 EPSS 3.41% Aug 2, 2017
CVE-2017-11174 CRITICAL

In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the da…

CVSS 9.8 EPSS 1.03% Jul 12, 2017
CVE-2017-7944 MEDIUM

XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php.

CVSS 6.1 EPSS 0.76% Apr 24, 2017
CVE-2017-7290 HIGH

SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via…

CVSS 7.2 EPSS 2.30% Mar 30, 2017
CVE-2014-8999 MEDIUM

SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated users to execute arbitrary SQL commands…

CVSS 6.5 EPSS 1.66% Nov 20, 2014
CVE-2012-0984 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) to_userid p…

CVSS 4.3 EPSS 4.16% Sep 11, 2014
CVE-2014-3935 HIGH

SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via the lettre…

CVSS 7.5 EPSS 2.08% Jun 2, 2014
CVE-2011-4565 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote attackers to inject arbitrary web script or H…

CVSS 4.3 EPSS 1.27% Nov 28, 2011
CVE-2011-3822 MEDIUM

XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error messag…

CVSS 5.0 EPSS 1.23% Sep 24, 2011
CVE-2009-4851 MEDIUM

The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows r…

CVSS 5.0 EPSS 1.21% May 7, 2010
CVE-2009-4582 HIGH

SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL commands via the id parame…

CVSS 7.5 EPSS 0.96% Jan 6, 2010
CVE-2009-3963 HIGH

Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.

CVSS 7.5 EPSS 1.65% Nov 17, 2009
CVE-2008-7178 HIGH

Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter…

CVSS 7.5 EPSS 2.17% Sep 8, 2009
CVE-2009-2783 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parameter to mo…

CVSS 4.3 EPSS 1.94% Aug 17, 2009
CVE-2008-6885 MEDIUM

Cross-site scripting (XSS) vulnerability in pmlite.php in XOOPS 2.3.1 and 2.3.2a allows remote attackers to inject arbitrary web script or HTML via a STYLE att…

CVSS 4.3 EPSS 1.29% Jul 31, 2009
CVE-2008-6884 MEDIUM

Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local fi…

CVSS 6.8 EPSS 5.62% Jul 31, 2009
CVE-2008-5665 HIGH

SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no parameter.

CVSS 7.5 EPSS 0.97% Dec 18, 2008
CVE-2008-4653 HIGH

SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrary SQL comm…

CVSS 7.5 EPSS 1.00% Oct 21, 2008
CVE-2008-3560 MEDIUM

Cross-site scripting (XSS) vulnerability in kshop_search.php in the Kshop module 2.22 for Xoops allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 EPSS 1.44% Aug 8, 2008
CVE-2008-3296 HIGH

Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a .. (…

CVSS 7.5 EPSS 5.71% Jul 25, 2008

Showing 1 to 25 CVEs · page 1 (more available)