VYPR
Vendor

XOOPS

XOOPS is a free open-source content management system (CMS), written in PHP. It uses a modular architecture allowing users to customize, update and theme their websites. XOOPS is released under the terms of the GNU General Public License (GPL) and is free to use, modify and redistribute.

Founded 2001
Products
69
CVEs
107
Across products
91
Status
Private

Products

69
View all 69 products →

Recent CVEs

107
View all 107 CVEs →
  • CVE-2017-11174CriJul 12, 2017
    risk 0.64cvss 9.8epss 0.01

    In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of GBK in CHARACTER SET and COLLATE clauses.

  • CVE-2023-36217CriAug 3, 2023
    risk 0.59cvss 9.0epss 0.02

    Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.

  • CVE-2019-25433HigFeb 22, 2026
    risk 0.53cvss 8.2epss 0.00

    XOOPS CMS 2.5.9 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the gerar_pdf.php endpoint with malicious cid values to extract…

  • CVE-2017-7290HigMar 30, 2017
    risk 0.47cvss 7.2epss 0.02

    SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.

  • CVE-2017-12139MedAug 2, 2017
    risk 0.40cvss 6.1epss 0.01

    XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.

  • CVE-2017-12138MedAug 2, 2017
    risk 0.40cvss 6.1epss 0.03

    XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.

  • CVE-2017-7944MedApr 24, 2017
    risk 0.40cvss 6.1epss 0.01

    XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php.

  • CVE-2019-16684MedSep 30, 2019
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is hovered over in the list or in the Edit page, the payload executes.

  • CVE-2019-16683MedSep 30, 2019
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered over while editing any image, a JavaScript payload executes.

  • CVE-2007-3236Jun 15, 2007
    risk 0.09cvss epss 0.77

    PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter.

  • CVE-2007-3237Jun 15, 2007
    risk 0.08cvss epss 0.68

    PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

  • CVE-2007-3220Jun 14, 2007
    risk 0.08cvss epss 0.63

    PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this may be a duplicate of CVE-2006-4656.

  • CVE-2007-3221Jun 14, 2007
    risk 0.08cvss epss 0.68

    PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

  • CVE-2007-3057Jun 6, 2007
    risk 0.08cvss epss 0.69

    PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

  • CVE-2007-3289Jun 20, 2007
    risk 0.04cvss epss 0.12

    PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

  • CVE-2007-3222Jun 14, 2007
    risk 0.04cvss epss 0.07

    PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the dir_module parameter.

  • CVE-2006-2516May 22, 2006
    risk 0.04cvss epss 0.06

    mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption['nocommon'] and conduct directory traversal attacks or include PHP files via (1) xoopsConfig[language] to misc.php or (2)…

  • CVE-2012-0984Sep 11, 2014
    risk 0.03cvss epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) to_userid parameter to modules/pm/pmlite.php or the (2) current_file, (3) imgcat_id, or (4) target parameter to…

  • CVE-2014-3935Jun 2, 2014
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via the lettre parameter.

  • CVE-2009-4714Mar 15, 2010
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the quiz module for XOOPS Celepar allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to cadastro_usuario.php.