Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thingsboard CRITICAL 9.1
CVE-2025-34282

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker …

Fix: 4.2.1+
Fix from $2,300 2025-10-17
Thingsboard MEDIUM 5.4
CVE-2025-34281

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cros…

Fix: 4.2.1+
Fix from $1,600 2025-10-17
Thingsboard MEDIUM 6.5
CVE-2024-55466

An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows at…

Fix: after 3.8.1
Fix from $1,600 2025-05-12
Thingsboard MEDIUM 5.9
CVE-2024-9358

A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality o…

Fix: after 3.7
Fix from $1,600 2024-10-01
Thingsboard MEDIUM 6.5
CVE-2024-3270

A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeat…

Fix: after 3.6.2
Fix from $1,600 2024-04-03
Thingsboard HIGH 8.8
CVE-2023-45303

ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports fre…

Fix: 3.5+
Fix from $1,950 2023-10-06
Thingsboard HIGH 8.8
CVE-2022-45608

An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an…

Mitigation only
Fix from $1,950 2023-03-01
Thingsboard HIGH 8.8
CVE-2022-48341

ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Admi…

Mitigation only
Fix from $1,950 2023-02-23
Thingsboard HIGH 8.1
CVE-2023-26462

ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) …

Mitigation only
Fix from $1,950 2023-02-23
Thingsboard CRITICAL 9.6
CVE-2022-40004

Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log.

Mitigation only
Fix from $2,300 2022-12-15
Thingsboard MEDIUM 5.4
CVE-2022-31861

Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.

Fix: after 3.3.4.1
Fix from $1,600 2022-09-13
Thingsboard HIGH 8.8
CVE-2020-27687

ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-…

Fix: 3.2+
Fix from $1,950 2020-12-18