CVE-2020-19914: Xiuno Xiunobbs

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) in xiunobbs 4.0.4 allows remote attackers to execute arbitrary web script or HTML via the attachment upload function.

Affected products

  • Xiuno Xiunobbs: version 4.0.4 only

Published 2022-09-07. Last modified 2026-06-17.