Xoops

Vendor:

First CVE: May 16, 2002 · Active for 24 years

59
Total CVEs
More Total CVEs than 98% of tracked products
4.2
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Xoops over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2002
24 years ago
Most Recent CVE
Aug 3, 2023
1,086 days ago

CVE Severity & Scoring

Xoops59 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (13.6%)
Unknown51 (86.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (13.6%)
High0 (0.0%)
Unknown51 (86.4%)
User Interaction
None2 (3.4%)
Unknown51 (86.4%)
Required6 (10.2%)
Privileges Required
Low1 (1.7%)
High3 (5.1%)
None4 (6.8%)
Unknown51 (86.4%)

Top CVEs

Signals from CVEs in this product scope (59 CVEs).

59 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.
Feb 6, 20087.531NOYES
SQL injection vulnerability in modules/content/index.php in the Content module 0.5 for XOOPS allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Dec 20, 20097.530NOYES
Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot
Jul 31, 20096.830NOYES
Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fct p
Jul 25, 20087.530NOYES
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page,
Jul 12, 20179.829NONO
Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang pa
Feb 6, 20087.529NOYES
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso
Mar 15, 20107.528NOYES
Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a downloadfile ac
Sep 8, 20097.528NOYES
SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.
Dec 30, 20087.528NOYES
SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no parameter.
Dec 19, 20087.528NOYES

Exploit Exposure

Signals from CVEs in this product scope (59 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.7% of CVEs· 96th percentile
ExploitDB
28 CVEs
47.5% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (59 CVEs).

Media Mentions

Signals from CVEs in this product scope (59 CVEs).

Top CNAs Publishing CVEs For Xoops

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.5.8.137.71.4%00
2.5.826.12.1%01
2.5.7.317.22.3%00
2.5.7.217.22.3%00
2.5.314.34.2%01
2.5.214.34.2%01
2.5.1036.21.1%00
2.5.124.32.7%01
2.5.034.52.2%01
2.4.514.31.3%00
2.4.414.31.3%00
2.4.314.31.3%00
2.4.214.31.3%00
2.4.114.31.3%00
2.4.0_rc15.01.2%00
2.4.0_beta_215.01.2%00
2.4.0_beta_115.01.2%00
2.4.014.31.3%00
2.3.3b14.31.3%00
2.3.334.51.5%01