Schiocco's vulnerability footprint concentrates in Support Board, a web-based help desk and chat platform, where disclosures skew strongly toward critical-severity outcomes and recur across application-layer input-handling and access-control issues. The vendor's exposure pattern reflects weaknesses typical of web applications: cross-site scripting, SQL injection, path traversal, authorization bypass, and cross-site request forgery—flaws that often emerge in rapid development cycles and affect deployments handling sensitive customer support data. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Schiocco over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27395CRITICAL Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. | Jun 16, 2026 | 9.8 | 32 | NO | NO |
CVE-2021-24741CRITICAL The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and r | Sep 20, 2021 | 9.8 | 32 | NO | NO |
CVE-2025-4855CRITICAL The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in | Jul 9, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-4815HIGH A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve, create, update and delete database via 'calls[0][message_id | Mar 25, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-4828CRITICAL The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete function in all versions up to, and i | Jul 9, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-54031HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board supportboard allows PHP Local File I | Aug 20, 2025 | 8.1 | 26 | NO | NO |
CVE-2021-24823HIGH The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users d | Feb 28, 2022 | 8.1 | 26 | NO | NO |
CVE-2025-54027HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board supportboard allows Reflected XSS.This issue affects Su | Aug 20, 2025 | 7.1 | 24 | NO | NO |
CVE-2025-60182HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board supportboard allows Reflected XSS.This issue affects Su | Dec 18, 2025 | 7.1 | 23 | NO | NO |
CVE-2026-4816MEDIUM A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to execute JavaScript code in the victim's browse | Mar 25, 2026 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Schiocco.
Media articles that mention a CVE ID that affects a product developed by Schiocco — matched by CVE ID, not by vendor name.