Vulnerability index

Browse CVEs

41 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-60859 Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via crafted c_id parameter in bb… Gnuboard Patch available Fix from $1,6002025-10-23 MEDIUM 6.5 CVE-2025-61464 gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php. Gnuboard after 4.36.04 Fix from $1,6002025-10-23 MEDIUM 5.4 CVE-2025-7786 A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects some unknown processing of the f… Gnuboard after 6.0.10 Fix from $1,6002025-07-18 MEDIUM 6.1 CVE-2024-37656 An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter veri… Gnuboard No fix yet Fix from $1,6002025-07-07 MEDIUM 6.1 CVE-2024-37657 An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component. Gnuboard Patch available Fix from $1,6002025-07-07 MEDIUM 6.1 CVE-2024-37658 An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php. Gnuboard Patch available Fix from $1,6002025-07-07 MEDIUM 6.1 CVE-2024-39097 There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path. Gnuboard 6.0.5+ Fix from $1,6002024-08-26 HIGH 8.8 CVE-2024-41475 Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration. Gnuboard No fix yet Fix from $1,9502024-08-12 MEDIUM 6.1 CVE-2024-24157 Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py. Gnuboard 6.0.0+ Fix from $1,6002024-05-14 MEDIUM 6.1 CVE-2024-24156 Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execut… Gnuboard 6.0.0+ Fix from $1,6002024-03-16 HIGH 7.5 CVE-2022-44216 Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original passwo… Gnuboard Patch available Fix from $1,9502023-02-20 MEDIUM 6.1 CVE-2021-4293 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in gnuboard youngcart5 up to 5.4.5.1. Affected is an unknown… Youngcart5 5.4.5.2+ Fix from $1,6002022-12-28 MEDIUM 5.4 CVE-2022-3963 A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the file bbs/faq.php of the compone… Gnuboard 5.5.8.2.1+ Fix from $1,6002022-11-12 MEDIUM 6.1 CVE-2022-30050 Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php. Gnuboard No fix yet Fix from $1,6002022-05-16 CRITICAL 9.1 CVE-2022-1252 Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5… Gnuboard after 5.5.5 Fix from $2,3002022-04-11 CRITICAL 9.8 CVE-2020-18662EPSS 5% SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. Gnuboard after 5.3.2.8 Fix from $2,3002021-06-24 MEDIUM 6.1 CVE-2020-18663 Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php. Gnuboard after 5.3.2.8 Fix from $1,6002021-06-24 MEDIUM 6.1 CVE-2020-18661 Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php. Gnuboard after 5.3.2.8 Fix from $1,6002021-06-24 MEDIUM 6.1 CVE-2018-18674 GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka the adm/bo… Gnuboard Patch available Fix from $1,6002019-11-07 MEDIUM 6.1 CVE-2018-18678 GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, … Gnuboard 5.3.2.0+ Fix from $1,6002019-10-30 MEDIUM 6.1 CVE-2018-18668 GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka the adm/… Gnuboard 5.3.2.0+ Fix from $1,6002019-08-26 MEDIUM 6.1 CVE-2017-18572 The gnucommerce plugin before 1.4.2 for WordPress has XSS. Gnucommerce 1.4.2+ Fix from $1,6002019-08-22 MEDIUM 6.1 CVE-2016-10920 The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS. Gnucommerce Mitigation only Fix from $1,6002019-08-22 MEDIUM 6.1 CVE-2018-18670 GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the adm/config_… Gnuboard Patch available Fix from $1,6002019-07-23 MEDIUM 6.1 CVE-2018-18672 GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka the adm/bo… Gnuboard Patch available Fix from $1,6002019-07-23 MEDIUM 6.1 CVE-2018-18675 GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board title contents" parameter, aka th… Gnuboard Patch available Fix from $1,6002019-07-23 MEDIUM 6.1 CVE-2018-18676 GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter, aka the… Gnuboard Patch available Fix from $1,6002019-07-23 MEDIUM 6.1 CVE-2018-18673 GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parameter, aka the adm/menu_list_up… Gnuboard Patch available Fix from $1,6002019-07-23 MEDIUM 6.1 CVE-2018-18671 GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head contents" parameter, aka the… Gnuboard Patch available Fix from $1,6002019-07-23 MEDIUM 6.1 CVE-2018-18669 GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board title contents" parameter, aka the adm/b… Gnuboard Patch available Fix from $1,6002019-07-23