Exbb's vulnerability profile is concentrated in a narrowly scoped portfolio of products, including Exbb Italia and its core platform, with a durable signal centered on application-layer input-handling and code-generation issues such as code injection, path traversal, and improper input validation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exbb over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1862MEDIUM ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which allows remote attackers to bypass this check via (1) POST or ( | Apr 17, 2008 | 6.8 | 29 | NO | YES |
CVE-2008-1861MEDIUM Directory traversal vulnerability in modules/threadstop/threadstop.php in ExBB Italia 0.22 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows re | Apr 17, 2008 | 5.1 | 24 | NO | YES |
CVE-2006-4488MEDIUM PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitr | Aug 31, 2006 | 5.1 | 23 | NO | YES |
CVE-2006-4544HIGH Multiple PHP remote file inclusion vulnerabilities in ExBB 1.9.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the exbb[home_ | Sep 6, 2006 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exbb.
Media articles that mention a CVE ID that affects a product developed by Exbb — matched by CVE ID, not by vendor name.