xataboost Vulnerabilities and Affected Products
Vulnerabilities associated with XATABoost CMS.
Products
Clear product- XATABoost CMS1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-25300HIGH | XATABoost CMS 1.0.0 SQL Injection via news.phpXATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information. CWE-89Apr 29, 2026 | CVSS8.8v4.0 | EPSS0.323% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |