CVE-2016-11020: Kunena

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.

Affected products

  • Kunena Kunena: before 5.0.4 (fixed in 5.0.4)

Published 2020-02-25. Last modified 2026-06-17.