E Xoops is a modestly represented content-management and portal framework with a focused product portfolio that appears in vulnerabilities spanning its core platform. The recurring exposure reflects typical web-application and integration complexity rather than a dominant structural weakness class. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by E Xoops over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6380HIGH Multiple SQL injection vulnerabilities in e-Xoops (exoops) 1.08, and 1.05 Rev 1 through 3, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to (a) | Dec 15, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-0828MEDIUM highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP | May 2, 2005 | 5.0 | 27 | NO | YES |
CVE-2008-7036MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, al | Aug 24, 2009 | 4.3 | 21 | NO | YES |
CVE-2005-0911HIGH Multiple SQL injection vulnerabilities in exoops may allow remote attackers to execute arbitrary SQL commands via (1) the viewcat parameter to index.php or (2) the artid parameter | Mar 28, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-0827MEDIUM Viewcat.php in (1) RUNCMS 1.1A, (2) Ciamos 0.9.2 RC1, e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allow remote attackers to obtain sensitive informati | May 2, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-1031MEDIUM RUNCMS 1.1A, and possibly other products based on e-Xoops (exoops), when "Allow custom avatar upload" is enabled, does not properly verify uploaded files, which allows remote attac | May 2, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-0910MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in exoops allow remote attackers to inject arbitrary web script or HTML via (1) the sortdays parameter to viewforum.php or (2) t | May 2, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by E Xoops.
Media articles that mention a CVE ID that affects a product developed by E Xoops — matched by CVE ID, not by vendor name.