Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Reviewboard

First CVE: Nov 24, 2011Active for: 15 yearsTotal CVEs: 13
17.6
VTI Score
Low

Reviewboard is a code-review and collaboration platform whose vulnerability profile concentrates in its core Review Board application and related components such as Djblets, sitting in the development workflow of engineering teams. The durable signal centers on web-application input-handling and authorization weaknesses including cross-site scripting, improper input validation, unrestricted file uploads, and access-control issues, alongside exposure of sensitive information—patterns characteristic of server-side web applications handling user-supplied content and role-based permissions. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Reviewboard over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 24, 2011
14 years ago
Most Recent CVE
May 11, 2022
1,535 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-4410HIGH
ReviewBoard: has an access-control problem in REST API
Dec 2, 20197.525NONO
CVE-2013-4409CRITICAL
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
Nov 4, 20199.825NONO
CVE-2013-4796HIGH
ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request
Dec 27, 20198.822NONO
CVE-2014-5028MEDIUM
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and
Mar 29, 20186.521NONO
CVE-2021-31330MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when u
May 11, 20225.419NONO
CVE-2013-4411MEDIUM
Review Board: URL processing gives unauthorized users access to review lists
Dec 3, 20194.318NONO
CVE-2014-5027MEDIUM
Cross-site scripting (XSS) vulnerability in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via a query param
Jul 25, 20144.318NONO
CVE-2013-4795MEDIUM
Cross-site scripting (XSS) vulnerability in the Submitters list in Review Board 1.6.x before 1.6.18 and 1.7.x before 1.7.12 allows remote attackers to inject arbitrary web script o
Apr 11, 20144.317NONO
CVE-2011-4312MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the commenting system in Review Board before 1.5.7 and 1.6.x before 1.6.3 allow remote attackers to inject arbitrary web scri
Nov 24, 20114.317NONO
CVE-2014-3995MEDIUM
Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django allows remote attackers to inject arbitra
Jun 16, 20144.316NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
77%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (46.2%)
Unknown7 (53.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (46.2%)
High0 (0.0%)
Unknown7 (53.8%)
User Interaction
None5 (38.5%)
Unknown7 (53.8%)
Required1 (7.7%)
Privileges Required
Low4 (30.8%)
High0 (0.0%)
None2 (15.4%)
Unknown7 (53.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Reviewboard.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Reviewboard — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Reviewboard's Products

View all 2 CNAs →

Top CWEs