Openbb develops a focused financial data and analysis platform that serves investors, traders, and fintech applications, occupying a niche position in the vulnerability landscape despite its prominence among specialized tooling. Its disclosed vulnerabilities center on web-application attack surface, particularly cross-site request forgery and related input-handling weaknesses inherent to browser-accessible data platforms. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openbb over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1965MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) red | Apr 25, 2004 | 4.3 | 31 | NO | YES |
CVE-2002-0330HIGH Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary script and steal cookies via Javascript in th | Jun 25, 2002 | 7.5 | 31 | NO | YES |
CVE-2005-1612HIGH SQL injection vulnerability in read.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to execute arbitrary SQL commands via the TID parameter. | May 16, 2005 | 7.5 | 30 | NO | YES |
CVE-2006-4722HIGH PHP remote file inclusion vulnerability in Open Bulletin Board (OpenBB) 1.0.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter | Sep 12, 2006 | 7.5 | 29 | NO | YES |
CVE-2004-1966HIGH Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) FID parameter in board | Dec 31, 2004 | 7.5 | 28 | NO | YES |
CVE-2005-1613MEDIUM Cross-site scripting (XSS) vulnerability in member.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to inject arbitrary web script or HTML via the reverse paramete | May 16, 2005 | 6.8 | 27 | NO | YES |
CVE-2002-1830MEDIUM Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.php with the action and ismod | Dec 31, 2002 | 5.0 | 25 | NO | YES |
CVE-2004-1968MEDIUM The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter. | Apr 26, 2004 | 5.0 | 23 | NO | YES |
CVE-2004-1967HIGH Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.php, or (6) moderator.php in Open Bulletin | Apr 25, 2004 | 8.8 | 22 | NO | NO |
CVE-2002-1829MEDIUM Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitrary web script or HTML via (1) myhome.ph | Dec 31, 2002 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openbb.
Media articles that mention a CVE ID that affects a product developed by Openbb — matched by CVE ID, not by vendor name.