Vulnerabilities (CVE)

Filtered by vendor Xoops Subscribe
Filtered by product Xoops
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-36217 1 Xoops 1 Xoops 2023-08-08 N/A 9.0 CRITICAL
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.
CVE-2017-11174 1 Xoops 1 Xoops 2017-07-27 7.5 HIGH 9.8 CRITICAL
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of GBK in CHARACTER SET and COLLATE clauses.