Layerbb is a modestly represented forum and community platform vendor whose vulnerability profile concentrates in a single product line and skews strongly toward critical-severity outcomes. The recurring exposure centers on fundamental web-application input-handling flaws, including cross-site scripting, SQL injection, cross-site request forgery, and unrestricted file uploads, which are characteristic of server-side web platforms and frequently acquire public exploit code. Defenders should treat this vendor's advisories as requiring prompt patching, particularly where instances are internet-facing; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Layerbb over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16531HIGH LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php. | Sep 20, 2019 | 8.8 | 38 | NO | YES |
CVE-2018-17996MEDIUM LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/. | Mar 21, 2019 | 6.5 | 31 | NO | YES |
CVE-2018-17988CRITICAL LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter. | Mar 7, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-13973CRITICAL LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used. | Jul 19, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-17997MEDIUM LayerBB 1.1.1 allows XSS via the titles of conversations (PMs). | Mar 21, 2019 | 6.1 | 29 | NO | YES |
CVE-2019-13974HIGH LayerBB 1.1.3 allows conversations.php/cmd/new CSRF. | Jul 19, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-13972MEDIUM LayerBB 1.1.3 allows XSS via the application/commands/new.php pm_title variable, a related issue to CVE-2019-17997. | Jul 19, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Layerbb.
Media articles that mention a CVE ID that affects a product developed by Layerbb — matched by CVE ID, not by vendor name.