Vulnerabilities > Hubzilla

DATE CVE VULNERABILITY TITLE RISK
2022-04-15 CVE-2022-27257 Unspecified vulnerability in Hubzilla
A PHP Local File Inclusion vulneraility in the default Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
network
low complexity
hubzilla
7.5
2022-04-15 CVE-2022-27258 Cross-site Scripting vulnerability in Hubzilla 7.0.3
Multiple Cross-Site Scripting (XSS) vulnerabilities in Hubzilla 7.0.3 and earlier allows remote attacker to include arbitrary web script or HTML via the rpath parameter.
network
hubzilla CWE-79
4.3
2022-04-13 CVE-2022-27256 Open Redirect vulnerability in Hubzilla
A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
network
hubzilla CWE-601
5.8