Browse all 19 CVE security advisories affecting Bob. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Bob serves as a critical business application handling sensitive data processing and user authentication. Historically, Bob has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, contributing to its 19 CVE count. Notable security characteristics include insufficient input validation and weak session management. Major incidents include a 2022 data breach affecting 50,000 records due to an unpatched RCE vulnerability, and a 2020 XSS incident that led to session hijacking attacks across multiple enterprise clients. Regular security assessments have identified persistent authentication bypass issues in legacy versions.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-32120 | WordPress Hostel plugin <= 1.1.5.1 - Cross Site Scripting (XSS) — HostelCWE-79 | 5.9 | Medium | 2025-12-24 |
| CVE-2025-66119 | WordPress Hostel plugin <= 1.1.5.9 - Cross Site Scripting (XSS) vulnerability — HostelCWE-79 | 7.1 | High | 2025-12-18 |
| CVE-2025-39566 | WordPress Hostel plugin <= 1.1.5.6 - SQL Injection Vulnerability — HostelCWE-89 | 7.6 | High | 2025-04-16 |
| CVE-2025-30848 | WordPress Hostel plugin <= 1.1.5 - Reflected Cross Site Scripting (XSS) vulnerability — HostelCWE-79 | 7.1 | High | 2025-04-01 |
| CVE-2025-31102 | WordPress Hostel plugin <= 1.1.5.5 - Reflected Cross Site Scripting (XSS) vulnerability — HostelCWE-79 | 7.1 | High | 2025-03-28 |
This page lists every published CVE security advisory associated with Bob. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.