Minibb operates a compact forum-software product line whose vulnerabilities concentrate in web-application input handling and data exposure, spanning weakness classes including cross-site scripting, SQL injection, and information disclosure. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of forum platforms as targets for defacement, credential harvesting, and account takeover. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Minibb over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-7156HIGH PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remote attackers to execute arbitr | Mar 7, 2007 | 10.0 | 36 | NO | YES |
CVE-2007-2317HIGH Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute ar | Apr 26, 2007 | 7.5 | 35 | NO | YES |
CVE-2006-3955HIGH Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) news.ph | Aug 1, 2006 | 7.5 | 32 | NO | YES |
CVE-2007-3272HIGH Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter in a register action. | Jun 19, 2007 | 7.8 | 29 | NO | YES |
CVE-2006-5673MEDIUM PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via | Nov 3, 2006 | 6.8 | 29 | NO | YES |
CVE-2006-3690HIGH Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to | Jul 21, 2006 | 7.5 | 29 | NO | YES |
CVE-2004-2456HIGH SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action. | Dec 31, 2004 | 7.5 | 29 | NO | YES |
CVE-2014-9254HIGH bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl injection attacks via the code parameter in an un | Dec 31, 2014 | 7.5 | 28 | NO | YES |
CVE-2007-5719HIGH SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL commands via the table parameter to index.php. | Oct 30, 2007 | 7.5 | 28 | NO | YES |
CVE-2008-2024MEDIUM Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script | Apr 30, 2008 | 4.3 | 27 | NO | YES |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Minibb.
Media articles that mention a CVE ID that affects a product developed by Minibb — matched by CVE ID, not by vendor name.