CVE-2011-4565

Xoops < 2.5.1.a - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to include/formdhtmltextarea_preview.php or (2) img BBCODE tag within the message parameter to pmlite.php (aka Private Message). NOTE: some of these details are obtained from third party information.

Scores

EPSS 0.0047
EPSS Percentile 64.6%

Classification

CWE
CWE-79
Status published

Affected Products (31)

xoops/xoops < 2.5.1.a
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
... and 16 more

Timeline

Published Nov 28, 2011
Tracked Since Feb 18, 2026