Deluxebb operates a single web-based application product that, despite a narrow footprint, ranks among the more prominent vendors in the vulnerability landscape, suggesting wide deployment or high visibility within specific user communities. The vendor's disclosures concentrate on application-layer weaknesses including SQL injection, cross-site scripting, improper authentication, and exposure of sensitive information—flaws characteristic of web application development and input-handling complexity. Notably, vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the accessibility of web-based attack surface and the ease of weaponizing input-validation flaws at scale. The consistent recurrence of these weakness classes across the product line underscores the persistence of fundamental web-application security challenges and should inform defenders' code-review and input-validation practices. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Deluxebb over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6237HIGH cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to | Dec 4, 2007 | 9.0 | 32 | NO | YES |
CVE-2006-2914MEDIUM PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posti | Jun 23, 2006 | 5.1 | 32 | NO | YES |
CVE-2010-4151MEDIUM SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the | Nov 3, 2010 | 6.8 | 31 | NO | YES |
CVE-2010-1859MEDIUM SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the memberc | May 7, 2010 | 6.8 | 30 | NO | YES |
CVE-2006-5154HIGH PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatefolder parameter. | Oct 5, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-4558HIGH DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensi | Sep 6, 2006 | 7.5 | 29 | NO | YES |
CVE-2009-4465HIGH DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and configuration information, log data, | Dec 30, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-1033HIGH SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder parameter, a different vector than CVE- | Mar 20, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-2194HIGH SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter. | May 14, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-3304HIGH SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL commands via the xmsn parameter. | Jun 29, 2006 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Deluxebb.
Media articles that mention a CVE ID that affects a product developed by Deluxebb — matched by CVE ID, not by vendor name.