Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-60859
Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via crafted c_id parameter in bb…
Gnuboard
Patch available
MEDIUM 6.5
CVE-2025-61464
gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php.
Gnuboard
after 4.36.04
MEDIUM 5.4
CVE-2025-7786
A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects some unknown processing of the f…
Gnuboard
after 6.0.10
MEDIUM 6.1
CVE-2024-37656
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter veri…
Gnuboard
No fix yet
MEDIUM 6.1
CVE-2024-37657
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component.
Gnuboard
Patch available
MEDIUM 6.1
CVE-2024-37658
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php.
Gnuboard
Patch available
MEDIUM 6.1
CVE-2024-39097
There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.
Gnuboard
6.0.5+
HIGH 8.8
CVE-2024-41475
Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
Gnuboard
No fix yet
MEDIUM 6.1
CVE-2024-24157
Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.
Gnuboard
6.0.0+
MEDIUM 6.1
CVE-2024-24156
Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execut…
Gnuboard
6.0.0+
HIGH 7.5
CVE-2022-44216
Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original passwo…
Gnuboard
Patch available
MEDIUM 6.1
CVE-2021-4293
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in gnuboard youngcart5 up to 5.4.5.1. Affected is an unknown…
Youngcart5
5.4.5.2+
MEDIUM 5.4
CVE-2022-3963
A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the file bbs/faq.php of the compone…
Gnuboard
5.5.8.2.1+
MEDIUM 6.1
CVE-2022-30050
Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php.
Gnuboard
No fix yet
CRITICAL 9.1
CVE-2022-1252
Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5…
Gnuboard
after 5.5.5
CRITICAL 9.8
CVE-2020-18662EPSS 5%
SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
Gnuboard
after 5.3.2.8
MEDIUM 6.1
CVE-2020-18663
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php.
Gnuboard
after 5.3.2.8
MEDIUM 6.1
CVE-2020-18661
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php.
Gnuboard
after 5.3.2.8
MEDIUM 6.1
CVE-2018-18674
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka the adm/bo…
Gnuboard
Patch available
MEDIUM 6.1
CVE-2018-18678
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, …
Gnuboard
5.3.2.0+
MEDIUM 6.1
CVE-2018-18668
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka the adm/…
Gnuboard
5.3.2.0+
MEDIUM 6.1
CVE-2017-18572
The gnucommerce plugin before 1.4.2 for WordPress has XSS.
Gnucommerce
1.4.2+
MEDIUM 6.1
CVE-2016-10920
The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.
Gnucommerce
Mitigation only
MEDIUM 6.1
CVE-2018-18670
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the adm/config_…
Gnuboard
Patch available
MEDIUM 6.1
CVE-2018-18672
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka the adm/bo…
Gnuboard
Patch available
MEDIUM 6.1
CVE-2018-18675
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board title contents" parameter, aka th…
Gnuboard
Patch available
MEDIUM 6.1
CVE-2018-18676
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter, aka the…
Gnuboard
Patch available
MEDIUM 6.1
CVE-2018-18673
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parameter, aka the adm/menu_list_up…
Gnuboard
Patch available
MEDIUM 6.1
CVE-2018-18671
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head contents" parameter, aka the…
Gnuboard
Patch available
MEDIUM 6.1
CVE-2018-18669
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board title contents" parameter, aka the adm/b…
Gnuboard
Patch available