Mxbb maintains a modestly represented portfolio of browser extension and media-related products, including KB Mods, ModsDB, MX Glance, MX Shotcast, and MX Tinies, that operate in client-side environments where code injection vulnerabilities present a recurring structural risk. The vendor's disclosures center on improper code generation and control mechanisms—the characteristic weakness of extension and script-injection contexts—and frequently acquire public exploit tooling. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mxbb over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6567HIGH PHP remote file inclusion vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to execute arbitrary PHP code via a | Dec 15, 2006 | 10.0 | 38 | NO | YES |
CVE-2007-2493HIGH PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the modul | May 4, 2007 | 10.0 | 36 | NO | YES |
CVE-2006-6568HIGH Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to include arbitrary files via a .. (dot | Dec 15, 2006 | 10.0 | 36 | NO | YES |
CVE-2007-2313HIGH PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path | Apr 26, 2007 | 7.5 | 30 | NO | YES |
CVE-2006-6553HIGH PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in | Dec 14, 2006 | 7.5 | 30 | NO | YES |
CVE-2006-6566HIGH PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary | Dec 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-6295MEDIUM PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 allows remote attackers to execute arbitrary PHP code via a URL | Dec 5, 2006 | 6.8 | 29 | NO | YES |
CVE-2006-2361HIGH PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary | May 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-6645HIGH PHP remote file inclusion vulnerability in language/lang_english/lang_admin.php in the Web Links (mx_links) 2.05 and earlier module for mxBB allows remote attackers to execute arbi | Dec 20, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6615HIGH PHP remote file inclusion vulnerability in includes/act_constants.php in the Activity Games (mx_act) 0.92 module for mxBB allows remote attackers to execute arbitrary PHP code via | Dec 18, 2006 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mxbb.
Media articles that mention a CVE ID that affects a product developed by Mxbb — matched by CVE ID, not by vendor name.