CVE-2017-11651: Nexusphp

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

NexusPHP V1.5 has XSS via a javascript: or data: URL in a UBBCode url tag.

Affected products

Published 2017-07-26. Last modified 2026-06-17.