Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xoops

First CVE: May 16, 2002Active for: 24 yearsTotal CVEs: 101
45.7
VTI Score
High

Xoops is a modular content-management and portal framework whose vulnerability footprint spans the platform itself and a range of community-developed extensions and modules, creating a broad attack surface across its ecosystem. The recurring weakness classes—SQL injection, cross-site scripting, path traversal, and sensitive-information exposure—reflect the input-handling and access-control demands of a web application framework and its plugin architecture; these are durable structural weaknesses that arise repeatedly as the platform and its modules evolve. Vulnerabilities affecting this vendor frequently acquire public exploit code, making disclosed flaws actionable for threat actors with relatively low barrier to entry. Defenders should monitor Xoops installations and their enabled modules closely, prioritize patching of community plugins that may lack coordinated release cycles, and assume that framework vulnerabilities will be tested and weaponized rapidly; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
101
Total CVEs
More Total CVEs than 99% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Xoops over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2002
24 years ago
Most Recent CVE
Aug 3, 2023
1,086 days ago

Products(43 total)

Top CVEs

Signals from CVEs in this vendor scope (101 CVEs).

101 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-3236HIGH
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_
Jun 15, 20077.570NOYES
CVE-2007-3220MEDIUM
PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to execute arbitrary PHP code via a U
Jun 14, 20076.865NOYES
CVE-2007-3237MEDIUM
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL
Jun 15, 20076.864NOYES
CVE-2007-3221MEDIUM
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in
Jun 14, 20076.864NOYES
CVE-2007-3057MEDIUM
PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a U
Jun 6, 20076.864NOYES
CVE-2007-3289HIGH
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the sp
Jun 20, 20077.533NOYES
CVE-2008-0847HIGH
SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary SQL commands via the articleid parameter.
Feb 21, 20087.532NOYES
CVE-2008-0611HIGH
SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.
Feb 6, 20087.531NOYES
CVE-2007-3222HIGH
PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the dir_module param
Jun 14, 20077.531NOYES
CVE-2007-1979HIGH
SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, pos
Apr 12, 20077.531NOYES
View all 101 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products101 CVEs
49%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (7.9%)
Unknown93 (92.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (7.9%)
High0 (0.0%)
Unknown93 (92.1%)
User Interaction
None2 (2.0%)
Unknown93 (92.1%)
Required6 (5.9%)
Privileges Required
Low1 (1.0%)
High3 (3.0%)
None4 (4.0%)
Unknown93 (92.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (101 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.0% of CVEs· 95th percentile
ExploitDB
65 CVEs
64.4% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xoops.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xoops — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xoops's Products

View all 2 CNAs →

Top CWEs