CVE-2019-16684: Xoops

Medium severity, CVSS 4.8. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is hovered over in the list or in the Edit page, the payload executes.

Affected products

  • Xoops Xoops: version 2.5.10 only

Published 2019-09-30. Last modified 2026-06-17.