Uxper Uxper

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Uxper product.

RSS Feeds for Uxper security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Uxper products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Uxper Sorted by Most Security Vulnerabilities since 2018

Uxper Golo6 vulnerabilities

Uxper Togo5 vulnerabilities

Uxper Civi3 vulnerabilities

Uxper Nuss2 vulnerabilities

Uxper Golo Framework1 vulnerability

By the Year

In 2026 there have been 6 vulnerabilities in Uxper with an average score of 7.5 out of ten. Last year, in 2025 Uxper had 11 security vulnerabilities published. Right now, Uxper is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 0.38

Year Vulnerabilities Average Score
2026 6 7.45
2025 11 7.83
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 1 9.80

It may take a day or so for new Uxper vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Uxper Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-57799 Jul 13, 2026
Nuss <=1.3.6 LFI via include/require Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Nuss nuss allows PHP Local File Inclusion.This issue affects Nuss: from n/a through <= 1.3.6.
Nuss
CVE-2026-57794 Jul 13, 2026
Golo Framework <=1.7.3 LFI via Unvalidated Include/Require Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a through <= 1.7.3.
Golo Framework
CVE-2026-27051 Mar 25, 2026
Golo <=1.7.0 Priv Escalation via Incorrect Priv Assign in uxper Golo component Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0.
Golo
CVE-2026-23973 Mar 25, 2026
Golo <=1.7.5 Reflected XSS via Improper Neutralization (CVE-2026-23973) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through < 1.7.5.
Golo
CVE-2026-23975 Jan 22, 2026
PHP LFI in Golo <1.7.5 (CVE-2026-23975) Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo golo allows PHP Local File Inclusion.This issue affects Golo: from n/a through < 1.7.5.
Golo
CVE-2026-23974 Jan 22, 2026
Missing Authorization in Golo Before 1.7.5 (uxper) Missing Authorization vulnerability in uxper Golo golo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Golo: from n/a through < 1.7.5.
Golo
CVE-2025-52739 Dec 31, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows Reflected XSS.This issue affects Sala: from n/a through 1.1.3.
CVE-2025-62037 Nov 06, 2025
Missing Auth in uxper Togo < 1.0.4 Missing Authorization vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.
Togo
CVE-2025-62036 Nov 06, 2025
XSS Vulnerability in Uxper Togo <1.0.4 via Improper Input Neutralization Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.
Togo
CVE-2025-62035 Nov 06, 2025
UXper Togo <=1.0.3 Deserialization of Untrusted Data Deserialization of Untrusted Data vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.
Togo
CVE-2025-62034 Nov 06, 2025
Incorrect Privilege Assignment in uxper Togo <1.0.4 Incorrect Privilege Assignment vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.
Togo
CVE-2025-62033 Nov 06, 2025
Missing Authorization in uxper Togo before 1.0.4 Missing Authorization vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.
Togo
CVE-2025-52827 Jun 27, 2025
Deserialization Vulnerability in uxper Nuss <1.3.3 Allows Object Injection Deserialization of Untrusted Data vulnerability in uxper Nuss nuss allows Object Injection.This issue affects Nuss: from n/a through <= 1.3.3.
Nuss
CVE-2024-13771 Mar 14, 2025
Auth Bypass in Civi Job Board Theme <=2.1.4 Lets Unauth Reset Passwords The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of user validation before changing a password. This makes it possible for unauthenticated attackers to change the password of arbitrary users, including administrators, if the attacker knows the username of the victim.
Civi
CVE-2024-13772 Mar 14, 2025
Auth Bypass CVE-2024-13772 in Civi WP Theme <=2.1.6.1 (fb_ajax_login) The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax_login_or_register and google_ajax_login_or_register actions. This makes it possible for unauthenticated attackers to login as any user as long as they have access to the email.
Civi
CVE-2024-13773 Mar 14, 2025
Civi Job Board Theme <=2.1.4: Info Exposure via Hard-Coded Credentials The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via hard-coded credentials. This makes it possible for unauthenticated attackers to extract sensitive data including LinkedIn client and secret keys.
Civi
CVE-2024-12876 Mar 07, 2025
Privilege Escalation via AT in Golo City Travel Guide WP Theme <=1.6.10 The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Golo
CVE-2020-23790 May 12, 2021
An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5. An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5.
Golo
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.