CVE-2019-16683: Xoops
Medium severity, CVSS 4.8. EPSS: 1% chance of exploitation in the next 30 days.
An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered over while editing any image, a JavaScript payload executes.
Affected products
- Xoops Xoops: version 2.5.10 only
Published 2019-09-30. Last modified 2026-06-17.