Softbb operates a niche web application product that exhibits a durable vulnerability profile centered on input-handling weaknesses, particularly cross-site scripting and SQL injection flaws characteristic of web application attack surfaces. While the vendor's disclosure volume remains modestly represented, vulnerabilities affecting the product show a strong tendency toward public exploit availability, making timely patching essential for deployments. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Softbb over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4632HIGH Multiple SQL injection vulnerabilities in SoftBB 0.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) groupe parameter in addmembre.php a | Sep 8, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-1327HIGH SQL injection vulnerability in reg.php in SoftBB 0.1 allows remote attackers to execute arbitrary SQL commands via the mail parameter. | Mar 21, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-4593MEDIUM Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter. | Sep 6, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-4631MEDIUM Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote authenticated users to upload and execute arbitrary PHP code via | Sep 8, 2006 | 6.5 | 26 | NO | YES |
CVE-2006-4633MEDIUM index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or invalid page[] parameter. | Sep 8, 2006 | 5.0 | 23 | NO | YES |
CVE-2014-9560HIGH SQL injection vulnerability in redir_last_post_list.php in SoftBB 0.1.3 allows remote attackers to execute arbitrary SQL commands via the post parameter. | Jan 15, 2015 | 7.5 | 22 | NO | NO |
CVE-2014-9561MEDIUM Cross-site scripting (XSS) vulnerability in redir_last_post_list.php in SoftBB 0.1.3 allows remote attackers to inject arbitrary web script or HTML via the post parameter. | Jan 15, 2015 | 4.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Softbb.
Media articles that mention a CVE ID that affects a product developed by Softbb — matched by CVE ID, not by vendor name.