Uxper
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Uxper product.
RSS Feeds for Uxper security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Uxper products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Uxper Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 6 vulnerabilities in Uxper with an average score of 7.5 out of ten. Last year, in 2025 Uxper had 11 security vulnerabilities published. Right now, Uxper is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 0.38
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 6 | 7.45 |
| 2025 | 11 | 7.83 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 1 | 9.80 |
It may take a day or so for new Uxper vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Uxper Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-57799 | Jul 13, 2026 |
Nuss <=1.3.6 LFI via include/requireImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Nuss nuss allows PHP Local File Inclusion.This issue affects Nuss: from n/a through <= 1.3.6. |
|
| CVE-2026-57794 | Jul 13, 2026 |
Golo Framework <=1.7.3 LFI via Unvalidated Include/RequireImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a through <= 1.7.3. |
|
| CVE-2026-27051 | Mar 25, 2026 |
Golo <=1.7.0 Priv Escalation via Incorrect Priv Assign in uxper Golo componentIncorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0. |
|
| CVE-2026-23973 | Mar 25, 2026 |
Golo <=1.7.5 Reflected XSS via Improper Neutralization (CVE-2026-23973)Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through < 1.7.5. |
|
| CVE-2026-23975 | Jan 22, 2026 |
PHP LFI in Golo <1.7.5 (CVE-2026-23975)Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo golo allows PHP Local File Inclusion.This issue affects Golo: from n/a through < 1.7.5. |
|
| CVE-2026-23974 | Jan 22, 2026 |
Missing Authorization in Golo Before 1.7.5 (uxper)Missing Authorization vulnerability in uxper Golo golo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Golo: from n/a through < 1.7.5. |
|
| CVE-2025-52739 | Dec 31, 2025 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper SalaImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows Reflected XSS.This issue affects Sala: from n/a through 1.1.3. |
|
| CVE-2025-62037 | Nov 06, 2025 |
Missing Auth in uxper Togo < 1.0.4Missing Authorization vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
|
| CVE-2025-62036 | Nov 06, 2025 |
XSS Vulnerability in Uxper Togo <1.0.4 via Improper Input NeutralizationImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
|
| CVE-2025-62035 | Nov 06, 2025 |
UXper Togo <=1.0.3 Deserialization of Untrusted DataDeserialization of Untrusted Data vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
|
| CVE-2025-62034 | Nov 06, 2025 |
Incorrect Privilege Assignment in uxper Togo <1.0.4Incorrect Privilege Assignment vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
|
| CVE-2025-62033 | Nov 06, 2025 |
Missing Authorization in uxper Togo before 1.0.4Missing Authorization vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
|
| CVE-2025-52827 | Jun 27, 2025 |
Deserialization Vulnerability in uxper Nuss <1.3.3 Allows Object InjectionDeserialization of Untrusted Data vulnerability in uxper Nuss nuss allows Object Injection.This issue affects Nuss: from n/a through <= 1.3.3. |
|
| CVE-2024-13771 | Mar 14, 2025 |
Auth Bypass in Civi Job Board Theme <=2.1.4 Lets Unauth Reset PasswordsThe Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of user validation before changing a password. This makes it possible for unauthenticated attackers to change the password of arbitrary users, including administrators, if the attacker knows the username of the victim. |
|
| CVE-2024-13772 | Mar 14, 2025 |
Auth Bypass CVE-2024-13772 in Civi WP Theme <=2.1.6.1 (fb_ajax_login)The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax_login_or_register and google_ajax_login_or_register actions. This makes it possible for unauthenticated attackers to login as any user as long as they have access to the email. |
|
| CVE-2024-13773 | Mar 14, 2025 |
Civi Job Board Theme <=2.1.4: Info Exposure via Hard-Coded CredentialsThe Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via hard-coded credentials. This makes it possible for unauthenticated attackers to extract sensitive data including LinkedIn client and secret keys. |
|
| CVE-2024-12876 | Mar 07, 2025 |
Privilege Escalation via AT in Golo City Travel Guide WP Theme <=1.6.10The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account. |
|
| CVE-2020-23790 | May 12, 2021 |
An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5.An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5. |
|