Vulnerabilities
Vulnerable Software
Kunena:  >> Kunena  >> 5.0.2  Security Vulnerabilities
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
CVSS Score
9.8
EPSS Score
0.034
Published
2020-02-25
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
CVSS Score
5.4
EPSS Score
0.014
Published
2019-08-16
In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScript, leading to XSS. Six files are affected: crypsis/layouts/message/item/default.php, crypsis/layouts/message/item/top/default.php, crypsis/layouts/message/item/bottom/default.php, crypsisb3/layouts/message/item/default.php, crypsisb3/layouts/message/item/top/default.php, and crypsisb3/layouts/message/item/bottom/default.php. This is fixed in 5.0.5.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-03-22


Contact Us

Shodan ® - All rights reserved