Pybbs Project maintains a lightweight, forum-oriented application that is niche but prominent among developers of bulletin-board systems, concentrated in a single product line. The vulnerability profile reflects the web-application context: recurring weaknesses cluster around input handling and output encoding—cross-site scripting, code injection, and CSRF—alongside information-disclosure issues that are characteristic of server-side template and request processing. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pybbs Project over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8550MEDIUM A vulnerability was found in atjiu pybbs up to 6.0.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/topic/list. | Aug 5, 2025 | 5.4 | 30 | NO | YES |
CVE-2020-28702HIGH A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database information. | Nov 1, 2021 | 7.5 | 25 | NO | NO |
CVE-2025-8813MEDIUM A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as problematic. This vulnerability affects the function changeLanguage of the file src/main/java/co/yiiu/py | Aug 10, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-8554MEDIUM A vulnerability, which was classified as problematic, has been found in atjiu pybbs up to 6.0.0. This issue affects some unknown processing of the file /admin/user/list. The manipu | Aug 5, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-8553MEDIUM A vulnerability classified as problematic was found in atjiu pybbs up to 6.0.0. This vulnerability affects unknown code of the file /admin/sensitive_word/list. The manipulation of | Aug 5, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-8551MEDIUM A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/comment/list. The ma | Aug 5, 2025 | 5.4 | 21 | NO | NO |
CVE-2022-23391MEDIUM A cross-site scripting (XSS) vulnerability in Pybbs v6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Search box. | Feb 14, 2022 | 6.1 | 21 | NO | NO |
CVE-2025-8812MEDIUM A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects an unknown part of the file /api/settings of the component Admin Panel. The | Aug 10, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-8555MEDIUM A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown function of the file /search. The manipulation of the argument ke | Aug 5, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-8547MEDIUM A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as critical. This vulnerability affects unknown code of the component Email Verification Handler. The manip | Aug 5, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pybbs Project.
Media articles that mention a CVE ID that affects a product developed by Pybbs Project — matched by CVE ID, not by vendor name.