Vulnerabilities > Xoops > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-08-03 CVE-2023-36217 Cross-site Scripting vulnerability in Xoops 2.5.10
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.
network
low complexity
xoops CWE-79
critical
9.0