Funkboard's vulnerability profile centers on a narrowly scoped product with a disproportionately high public-exploit tendency relative to its modest vulnerability count, indicating that disclosed flaws attract tooling and weaponization readily. The product's weaknesses are categorized within NVD placeholder taxonomy, limiting structural inference about underlying patterns; however, the consistent public-exploit inclination suggests the product may be attractive for proof-of-concept or penetration-testing frameworks. Defenders deploying this product should treat available exploit code as a patching signal and prioritize updates; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Funkboard over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2896MEDIUM profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form field in an Edit Profile action. | Jun 7, 2006 | 5.0 | 29 | NO | YES |
CVE-2005-2569MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbuser | Aug 16, 2005 | 4.3 | 24 | NO | YES |
CVE-2006-5775MEDIUM Cross-site scripting (XSS) vulnerability in profile.php in FunkBoard 0.71 before 4 November 2006 at 18:16 GMT allows remote attackers to inject arbitrary web script or HTML, possib | Nov 6, 2006 | 6.8 | 18 | NO | NO |
CVE-2005-2571MEDIUM FunkBoard 0.66CF, and possibly earlier versions, does not properly restrict access to the (1) admin/mysql_install.php and (2) admin/pg_install.php scripts, which allows attackers t | Aug 16, 2005 | 6.4 | 17 | NO | NO |
CVE-2005-2570MEDIUM FunkBoard 0.66CF, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to forums.php, which reveals the path in an error mess | Aug 16, 2005 | 5.0 | 15 | NO | NO |
Cross-site scripting (XSS) vulnerability in FunkBoard 0.71 allows remote attackers to inject arbitrary HTML or web script via unspecified vectors. | Jun 7, 2006 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Funkboard.
Media articles that mention a CVE ID that affects a product developed by Funkboard — matched by CVE ID, not by vendor name.