Vulnerability index

Browse CVEs

41 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gnuboard MEDIUM 6.1
CVE-2025-60859

Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via crafted c_id parameter in bb…

Patch available
Fix from $1,600 2025-10-23
Gnuboard MEDIUM 6.5
CVE-2025-61464

gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php.

Fix: after 4.36.04
Fix from $1,600 2025-10-23
Gnuboard MEDIUM 5.4
CVE-2025-7786

A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects some unknown processing of the f…

Fix: after 6.0.10
Fix from $1,600 2025-07-18
Gnuboard MEDIUM 6.1
CVE-2024-37656

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter veri…

No fix yet
Fix from $1,600 2025-07-07
Gnuboard MEDIUM 6.1
CVE-2024-37657

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component.

Patch available
Fix from $1,600 2025-07-07
Gnuboard MEDIUM 6.1
CVE-2024-37658

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php.

Patch available
Fix from $1,600 2025-07-07
Gnuboard MEDIUM 6.1
CVE-2024-39097

There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.

Fix: 6.0.5+
Fix from $1,600 2024-08-26
Gnuboard HIGH 8.8
CVE-2024-41475

Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

No fix yet
Fix from $1,950 2024-08-12
Gnuboard MEDIUM 6.1
CVE-2024-24157

Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.

Fix: 6.0.0+
Fix from $1,600 2024-05-14
Gnuboard MEDIUM 6.1
CVE-2024-24156

Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execut…

Fix: 6.0.0+
Fix from $1,600 2024-03-16
Gnuboard HIGH 7.5
CVE-2022-44216

Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original passwo…

Patch available
Fix from $1,950 2023-02-20
Youngcart5 MEDIUM 6.1
CVE-2021-4293

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in gnuboard youngcart5 up to 5.4.5.1. Affected is an unknown…

Fix: 5.4.5.2+
Fix from $1,600 2022-12-28
Gnuboard MEDIUM 5.4
CVE-2022-3963

A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the file bbs/faq.php of the compone…

Fix: 5.5.8.2.1+
Fix from $1,600 2022-11-12
Gnuboard MEDIUM 6.1
CVE-2022-30050

Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php.

No fix yet
Fix from $1,600 2022-05-16
Gnuboard CRITICAL 9.1
CVE-2022-1252

Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5…

Fix: after 5.5.5
Fix from $2,300 2022-04-11
Gnuboard CRITICAL 9.8
CVE-2020-18662EPSS 5%

SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.

Fix: after 5.3.2.8
Fix from $2,300 2021-06-24
Gnuboard MEDIUM 6.1
CVE-2020-18663

Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php.

Fix: after 5.3.2.8
Fix from $1,600 2021-06-24
Gnuboard MEDIUM 6.1
CVE-2020-18661

Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php.

Fix: after 5.3.2.8
Fix from $1,600 2021-06-24
Gnuboard MEDIUM 6.1
CVE-2018-18674

GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka the adm/bo…

Patch available
Fix from $1,600 2019-11-07
Gnuboard MEDIUM 6.1
CVE-2018-18678

GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, …

Fix: 5.3.2.0+
Fix from $1,600 2019-10-30
Gnuboard MEDIUM 6.1
CVE-2018-18668

GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka the adm/…

Fix: 5.3.2.0+
Fix from $1,600 2019-08-26
Gnucommerce MEDIUM 6.1
CVE-2017-18572

The gnucommerce plugin before 1.4.2 for WordPress has XSS.

Fix: 1.4.2+
Fix from $1,600 2019-08-22
Gnucommerce MEDIUM 6.1
CVE-2016-10920

The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.

Mitigation only
Fix from $1,600 2019-08-22
Gnuboard MEDIUM 6.1
CVE-2018-18670

GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the adm/config_…

Patch available
Fix from $1,600 2019-07-23
Gnuboard MEDIUM 6.1
CVE-2018-18672

GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka the adm/bo…

Patch available
Fix from $1,600 2019-07-23
Gnuboard MEDIUM 6.1
CVE-2018-18675

GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board title contents" parameter, aka th…

Patch available
Fix from $1,600 2019-07-23
Gnuboard MEDIUM 6.1
CVE-2018-18676

GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter, aka the…

Patch available
Fix from $1,600 2019-07-23
Gnuboard MEDIUM 6.1
CVE-2018-18673

GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parameter, aka the adm/menu_list_up…

Patch available
Fix from $1,600 2019-07-23
Gnuboard MEDIUM 6.1
CVE-2018-18671

GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head contents" parameter, aka the…

Patch available
Fix from $1,600 2019-07-23
Gnuboard MEDIUM 6.1
CVE-2018-18669

GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board title contents" parameter, aka the adm/b…

Patch available
Fix from $1,600 2019-07-23