Browse all 6 CVE security advisories affecting Xenioushk. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Xenioushk develops network security appliances focusing on threat detection and prevention. Historically, its products have been vulnerable to remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from improper input validation and authentication bypasses. The vendor has addressed six CVEs to date, with several critical RCE vulnerabilities allowing unauthenticated attackers to execute arbitrary code. While no major public incidents have been documented, the consistent presence of similar vulnerability patterns suggests potential weaknesses in input sanitization and access control mechanisms. Security researchers have noted that patch adoption remains a concern for some legacy products.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-4075 | BWL Advanced FAQ Manager Lite <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sbox_id' Shortcode Attribute — BWL Advanced FAQ Manager LiteCWE-79 | 6.4 | Medium | 2026-03-26 |
This page lists every published CVE security advisory associated with Xenioushk. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.