CVE-2017-12139: Xoops

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.

Affected products

  • Xoops Xoops: version 2.5.8 only

Published 2017-08-02. Last modified 2026-06-17.