Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Minibb

First CVE: Dec 31, 2004Active for: 22 yearsTotal CVEs: 18
51.5
VTI Score
TOP TARGET

Minibb operates a compact forum-software product line whose vulnerabilities concentrate in web-application input handling and data exposure, spanning weakness classes including cross-site scripting, SQL injection, and information disclosure. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of forum platforms as targets for defacement, credential harvesting, and account takeover. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Minibb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Feb 12, 2018
3,084 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-7156HIGH
PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remote attackers to execute arbitr
Mar 7, 200710.036NOYES
CVE-2007-2317HIGH
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute ar
Apr 26, 20077.535NOYES
CVE-2006-3955HIGH
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) news.ph
Aug 1, 20067.532NOYES
CVE-2007-3272HIGH
Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter in a register action.
Jun 19, 20077.829NOYES
CVE-2006-5673MEDIUM
PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via
Nov 3, 20066.829NOYES
CVE-2006-3690HIGH
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to
Jul 21, 20067.529NOYES
CVE-2004-2456HIGH
SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action.
Dec 31, 20047.529NOYES
CVE-2014-9254HIGH
bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl injection attacks via the code parameter in an un
Dec 31, 20147.528NOYES
CVE-2007-5719HIGH
SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL commands via the table parameter to index.php.
Oct 30, 20077.528NOYES
CVE-2008-2024MEDIUM
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script
Apr 30, 20084.327NOYES
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
39%
61%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (5.6%)
Unknown17 (94.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (5.6%)
High0 (0.0%)
Unknown17 (94.4%)
User Interaction
None0 (0.0%)
Unknown17 (94.4%)
Required1 (5.6%)
Privileges Required
Low0 (0.0%)
High1 (5.6%)
None0 (0.0%)
Unknown17 (94.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
13 CVEs
72.2% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Minibb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Minibb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Minibb's Products

View all 1 CNAs →

Top CWEs