VYPR

Question2answer

by Question2answer

Source repositories

CVEs (3)

  • CVE-2017-12775HigAug 29, 2017
    risk 0.49cvss 7.5epss 0.02

    qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts.

  • CVE-2026-64829HigJul 22, 2026
    risk 0.41cvss 7.4epss 0.00

    Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in…

  • CVE-2021-3258MedFeb 5, 2021
    risk 0.00cvss 5.4epss 0.02

    Question2Answer Q2A Ultimate SEO Version 1.3 is affected by cross-site scripting (XSS), which may lead to arbitrary remote code execution.