Vulnerabilities > Kunena > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-02-25 CVE-2016-11020 Unrestricted Upload of File with Dangerous Type vulnerability in Kunena
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png.
network
low complexity
kunena CWE-434
critical
9.8