CVE-2017-12139: Xoops
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.
Affected products
- Xoops Xoops: version 2.5.8 only
Published 2017-08-02. Last modified 2026-06-17.