Xoops is a modular content-management and portal framework whose vulnerability footprint spans the platform itself and a range of community-developed extensions and modules, creating a broad attack surface across its ecosystem. The recurring weakness classes—SQL injection, cross-site scripting, path traversal, and sensitive-information exposure—reflect the input-handling and access-control demands of a web application framework and its plugin architecture; these are durable structural weaknesses that arise repeatedly as the platform and its modules evolve. Vulnerabilities affecting this vendor frequently acquire public exploit code, making disclosed flaws actionable for threat actors with relatively low barrier to entry. Defenders should monitor Xoops installations and their enabled modules closely, prioritize patching of community plugins that may lack coordinated release cycles, and assume that framework vulnerabilities will be tested and weaponized rapidly; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xoops over time
Signals from CVEs in this vendor scope (101 CVEs).
101 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3236HIGH PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_ | Jun 15, 2007 | 7.5 | 70 | NO | YES |
CVE-2007-3220MEDIUM PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to execute arbitrary PHP code via a U | Jun 14, 2007 | 6.8 | 65 | NO | YES |
CVE-2007-3237MEDIUM PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL | Jun 15, 2007 | 6.8 | 64 | NO | YES |
CVE-2007-3221MEDIUM PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in | Jun 14, 2007 | 6.8 | 64 | NO | YES |
CVE-2007-3057MEDIUM PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a U | Jun 6, 2007 | 6.8 | 64 | NO | YES |
CVE-2007-3289HIGH PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the sp | Jun 20, 2007 | 7.5 | 33 | NO | YES |
CVE-2008-0847HIGH SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary SQL commands via the articleid parameter. | Feb 21, 2008 | 7.5 | 32 | NO | YES |
CVE-2008-0611HIGH SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 6, 2008 | 7.5 | 31 | NO | YES |
CVE-2007-3222HIGH PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the dir_module param | Jun 14, 2007 | 7.5 | 31 | NO | YES |
CVE-2007-1979HIGH SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, pos | Apr 12, 2007 | 7.5 | 31 | NO | YES |
Signals from CVEs in this vendor scope (101 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xoops.
Media articles that mention a CVE ID that affects a product developed by Xoops — matched by CVE ID, not by vendor name.