Pybb Project maintains a focused forum software product that operates as a Django-based discussion platform, with its vulnerability footprint concentrated in application-layer input-handling defects. The observed weakness classes center on cross-site scripting and SQL injection, reflecting the authentication and data-validation demands of a web application designed to manage user-generated content and forum interactions. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pybb Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34249CRITICAL benjjvi/PyBB is an open source bulletin board. Prior to commit dcaeccd37198ecd3e41ea766d1099354b60d69c2, benjjvi/PyBB is vulnerable to SQL Injection. This vulnerability has been fi | Jun 13, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-34461MEDIUM PyBB is an open source bulletin board. A manual code review of the PyBB bulletin board server has revealed that a vulnerability could have been exploited in which users could submi | Jun 19, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pybb Project.
Media articles that mention a CVE ID that affects a product developed by Pybb Project — matched by CVE ID, not by vendor name.