Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Deluxebb

First CVE: Sep 20, 2005Active for: 21 yearsTotal CVEs: 29
50.2
VTI Score
TOP TARGET

Deluxebb operates a single web-based application product that, despite a narrow footprint, ranks among the more prominent vendors in the vulnerability landscape, suggesting wide deployment or high visibility within specific user communities. The vendor's disclosures concentrate on application-layer weaknesses including SQL injection, cross-site scripting, improper authentication, and exposure of sensitive information—flaws characteristic of web application development and input-handling complexity. Notably, vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the accessibility of web-based attack surface and the ease of weaponizing input-validation flaws at scale. The consistent recurrence of these weakness classes across the product line underscores the persistence of fundamental web-application security challenges and should inform defenders' code-review and input-validation practices. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
4.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Deluxebb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 20, 2005
20 years ago
Most Recent CVE
Sep 23, 2011
5,418 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-6237HIGH
cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to
Dec 4, 20079.032NOYES
CVE-2006-2914MEDIUM
PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posti
Jun 23, 20065.132NOYES
CVE-2010-4151MEDIUM
SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the
Nov 3, 20106.831NOYES
CVE-2010-1859MEDIUM
SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the memberc
May 7, 20106.830NOYES
CVE-2006-5154HIGH
PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatefolder parameter.
Oct 5, 20067.529NOYES
CVE-2006-4558HIGH
DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensi
Sep 6, 20067.529NOYES
CVE-2009-4465HIGH
DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and configuration information, log data,
Dec 30, 20097.528NOYES
CVE-2009-1033HIGH
SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder parameter, a different vector than CVE-
Mar 20, 20097.528NOYES
CVE-2008-2194HIGH
SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.
May 14, 20087.528NOYES
CVE-2006-3304HIGH
SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL commands via the xmsn parameter.
Jun 29, 20067.528NOYES
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
48%
45%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown29 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown29 (100.0%)
User Interaction
None0 (0.0%)
Unknown29 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown29 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
18 CVEs
62.1% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Deluxebb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Deluxebb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Deluxebb's Products

View all 1 CNAs →

Top CWEs