HooskCVEs & Vulnerabilities

14 CVEs affecting Hoosk products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

hoosk 14
CVE-2025-25991MEDIUM

SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.

14 Feb 2025
5.1
CVSS
CVE-2025-25990MEDIUM

Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.

14 Feb 2025
6.1
CVSS
CVE-2025-25988MEDIUM

Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custom Link title parameter and the Title parameter.

14 Feb 2025
4.8
CVSS
CVE-2024-51055MEDIUM

An issue Hoosk v1.7.1 allows a remote attacker to execute arbitrary code via a crafted script to the config.php component.

8 Nov 2024
6.5
CVSS
CVE-2022-43234CRITICAL

An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file.

16 Nov 2022
9.8
CVSS
CVE-2022-28586MEDIUM

XSS in edit page of Hoosk 1.8.0 allows attacker to execute javascript code in user browser via edit page with XSS payload bypass filter some special chars.

25 Apr 2022
6.1
CVSS
CVE-2021-43478MEDIUM

A vulnerability exists in Hoosk 1.8.0 in /install/index.php, due to a failure to check if config.php already exists in the root directory, which could let a malicious user reinstall the website.

31 Mar 2022
5.4
CVSS
CVE-2020-26043MEDIUM

An issue was discovered in Hoosk CMS v1.8.0. There is a XSS vulnerability in install/index.php

30 Sep 2020
6.1
CVSS
CVE-2020-26042CRITICAL

An issue was discovered in Hoosk CMS v1.8.0. There is a SQL injection vulnerability in install/index.php

30 Sep 2020
9.8
CVSS
CVE-2020-26041CRITICAL

An issue was discovered in Hoosk CmS v1.8.0. There is an Remote Code Execution vulnerability in install/index.php

30 Sep 2020
9.8
CVSS
CVE-2020-16610MEDIUM

Hoosk Codeigniter CMS before 1.7.2 is affected by a Cross Site Request Forgery (CSRF). When an attacker induces authenticated admin user to a malicious web page, any accounts can be deleted without admin user's intention.

28 Aug 2020
4.3
CVSS
CVE-2018-16772MEDIUM

Hoosk v1.7.0 allows XSS via the Navigation Title of a new page entered at admin/pages/new.

10 Sep 2018
4.8
CVSS
CVE-2018-16771CRITICAL

Hoosk v1.7.0 allows PHP code execution via a SiteUrl that is provided during installation and mishandled in config.php.

10 Sep 2018
9.8
CVSS
CVE-2018-7590HIGH

CSRF exists in Hoosk 1.7.0 via /admin/users/new/add, resulting in account creation.

2 Mar 2018
8.8
CVSS
← PrevPage 1 / 1Next →
Hoosk CVEs & Vulnerabilities — 14 Tracked