Xiuno's vulnerability profile centers on its XiunoBBS forum software, a niche community platform where the durable signal reflects application-layer input-handling and data-processing challenges such as cross-site scripting, XML external entity injection, and related web-application flaws. The exposure is narrowly scoped to this product line and does not represent a broadly distributed attack surface. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xiuno over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19998HIGH Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php. | Dec 26, 2019 | 7.5 | 25 | NO | NO |
CVE-2020-19914MEDIUM Cross Site Scripting (XSS) in xiunobbs 4.0.4 allows remote attackers to execute arbitrary web script or HTML via the attachment upload function. | Sep 7, 2022 | 6.1 | 22 | NO | NO |
CVE-2020-21495MEDIUM A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitename p | Oct 4, 2021 | 6.1 | 22 | NO | NO |
CVE-2018-15559MEDIUM The editor in Xiuno BBS 4.0.4 allows stored XSS. | Aug 20, 2018 | 6.1 | 21 | NO | NO |
CVE-2020-21493MEDIUM An issue in the component route\user.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames. | Oct 4, 2021 | 5.3 | 20 | NO | NO |
CVE-2020-21496MEDIUM A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitebrief | Oct 4, 2021 | 6.1 | 17 | NO | NO |
CVE-2020-21494MEDIUM A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via changing the doctyp | Oct 4, 2021 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xiuno.
Media articles that mention a CVE ID that affects a product developed by Xiuno — matched by CVE ID, not by vendor name.