7.2 High
AI Score
Confidence
High
0.016 Low
EPSS
Percentile
87.3%
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
github.com/Kunena/Kunena-Forum/pull/5028
www.kunena.org/blog/179-kunena-5-0-4-released
www.kunena.org/bugs/changelog