Askbot is a focused question-and-answer platform that, despite a narrow product footprint, occupies a niche role in community-driven knowledge sharing and support systems. The durable vulnerability signal centers on web-application input-handling weaknesses, specifically cross-site scripting and authorization-bypass flaws that arise from user-controlled data in page generation and access-control logic; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Askbot over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1213MEDIUM All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue | Jan 27, 2026 | 4.3 | 17 | NO | NO |
CVE-2015-3169MEDIUM Cross-site scripting (XSS) vulnerability in askbot 0.7.51-4.el6.noarch. | Sep 7, 2017 | 6.1 | 17 | NO | NO |
CVE-2014-2236MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Askbot before 0.7.49 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) tag or (2) | Mar 5, 2014 | 4.3 | 17 | NO | NO |
CVE-2014-2235MEDIUM Cross-site scripting (XSS) vulnerability in Askbot before 0.7.49 allows remote attackers to inject arbitrary web script or HTML via vectors related to the question search form. | Mar 5, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Askbot.
Media articles that mention a CVE ID that affects a product developed by Askbot — matched by CVE ID, not by vendor name.