VYPR

BBS

by Xiuno

CVEs (7)

  • CVE-2019-19998HigDec 26, 2019
    risk 0.49cvss 7.5epss 0.01

    Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.

  • CVE-2020-21496MedOct 4, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitebrief parameter.

  • CVE-2020-21495MedOct 4, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitename parameter.

  • CVE-2020-21494MedOct 4, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via changing the doctype value to 0.

  • CVE-2018-15559MedAug 20, 2018
    risk 0.40cvss 6.1epss 0.01

    The editor in Xiuno BBS 4.0.4 allows stored XSS.

  • CVE-2020-21493MedOct 4, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue in the component route\user.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames.

  • CVE-2018-8942MedMar 22, 2018
    risk 0.35cvss 5.4epss 0.01

    Xiuno BBS 4.0.0 has XSS in the adminpage sitename parameter.