Mangboard maintains a focused suite of web-based commerce and content-management products that serve as targeted attack surfaces for input-handling and request-validation flaws. The vendor's disclosed vulnerabilities cluster around SQL injection, cross-site scripting, cross-site request forgery, and broader input-validation weaknesses characteristic of web application development, particularly in plugin-oriented and e-commerce environments. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mangboard over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26644CRITICAL SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnera | Jan 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-26631HIGH Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote attacker can exploit this vulnerability to manipulate the t | May 19, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-26609HIGH A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type parameter. The order_type parameter makes a SQL query using unfilter | Oct 26, 2021 | 7.5 | 25 | NO | NO |
CVE-2023-44257HIGH Cross-Site Request Forgery (CSRF) vulnerability in Hometory Mang Board WP plugin <= 1.7.6 versions. | Oct 10, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-22306MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Stored XSS.This issue affects Mang Board WP: fro | Jan 31, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mangboard.
Media articles that mention a CVE ID that affects a product developed by Mangboard — matched by CVE ID, not by vendor name.