Vulnerabilities
Vulnerable Software
Xiuno:  >> Xiunobbs  Security Vulnerabilities
Cross Site Scripting (XSS) in xiunobbs 4.0.4 allows remote attackers to execute arbitrary web script or HTML via the attachment upload function.
CVSS Score
6.1
EPSS Score
0.001
Published
2022-09-07
An issue in the component route\user.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames.
CVSS Score
5.3
EPSS Score
0.002
Published
2021-10-04
A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via changing the doctype value to 0.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-10-04
A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitename parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-10-04
A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitebrief parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-10-04
Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.
CVSS Score
7.5
EPSS Score
0.004
Published
2019-12-26
The editor in Xiuno BBS 4.0.4 allows stored XSS.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-08-20


Contact Us

Shodan ® - All rights reserved