Xoops
Vendor:
First CVE: May 16, 2002 · Active for 24 years
59
Total CVEs
More Total CVEs than 98% of tracked products
4.2
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Xoops over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2002
24 years ago
Most Recent CVE
Aug 3, 2023
1,086 days ago
CVE Severity & Scoring
Xoops59 CVEs
61%
36%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (13.6%)
Unknown51 (86.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (13.6%)
High0 (0.0%)
Unknown51 (86.4%)
User Interaction
None2 (3.4%)
Unknown51 (86.4%)
Required6 (10.2%)
Privileges Required
Low1 (1.7%)
High3 (5.1%)
None4 (6.8%)
Unknown51 (86.4%)
Top CVEs
Signals from CVEs in this product scope (59 CVEs).
59 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0611HIGH SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 6, 2008 | 7.5 | 31 | NO | YES |
CVE-2009-4360HIGH SQL injection vulnerability in modules/content/index.php in the Content module 0.5 for XOOPS allows remote attackers to inject arbitrary web script or HTML via the id parameter. | Dec 20, 2009 | 7.5 | 30 | NO | YES |
CVE-2008-6884MEDIUM Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot | Jul 31, 2009 | 6.8 | 30 | NO | YES |
CVE-2008-3296HIGH Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fct p | Jul 25, 2008 | 7.5 | 30 | NO | YES |
CVE-2017-11174CRITICAL In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, | Jul 12, 2017 | 9.8 | 29 | NO | NO |
CVE-2008-0612HIGH Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang pa | Feb 6, 2008 | 7.5 | 29 | NO | YES |
CVE-2009-4698HIGH Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso | Mar 15, 2010 | 7.5 | 28 | NO | YES |
CVE-2008-7178HIGH Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a downloadfile ac | Sep 8, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-5768HIGH SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter. | Dec 30, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5665HIGH SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no parameter. | Dec 19, 2008 | 7.5 | 28 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (59 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.7% of CVEs· 96th percentile
ExploitDB
28 CVEs
47.5% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (59 CVEs).
Media Mentions
Signals from CVEs in this product scope (59 CVEs).
Top CNAs Publishing CVEs For Xoops
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.5.8.1 | 3 | 7.7 | 1.4% | 0 | 0 |
| 2.5.8 | 2 | 6.1 | 2.1% | 0 | 1 |
| 2.5.7.3 | 1 | 7.2 | 2.3% | 0 | 0 |
| 2.5.7.2 | 1 | 7.2 | 2.3% | 0 | 0 |
| 2.5.3 | 1 | 4.3 | 4.2% | 0 | 1 |
| 2.5.2 | 1 | 4.3 | 4.2% | 0 | 1 |
| 2.5.10 | 3 | 6.2 | 1.1% | 0 | 0 |
| 2.5.1 | 2 | 4.3 | 2.7% | 0 | 1 |
| 2.5.0 | 3 | 4.5 | 2.2% | 0 | 1 |
| 2.4.5 | 1 | 4.3 | 1.3% | 0 | 0 |
| 2.4.4 | 1 | 4.3 | 1.3% | 0 | 0 |
| 2.4.3 | 1 | 4.3 | 1.3% | 0 | 0 |
| 2.4.2 | 1 | 4.3 | 1.3% | 0 | 0 |
| 2.4.1 | 1 | 4.3 | 1.3% | 0 | 0 |
| 2.4.0_rc | 1 | 5.0 | 1.2% | 0 | 0 |
| 2.4.0_beta_2 | 1 | 5.0 | 1.2% | 0 | 0 |
| 2.4.0_beta_1 | 1 | 5.0 | 1.2% | 0 | 0 |
| 2.4.0 | 1 | 4.3 | 1.3% | 0 | 0 |
| 2.3.3b | 1 | 4.3 | 1.3% | 0 | 0 |
| 2.3.3 | 3 | 4.5 | 1.5% | 0 | 1 |