Thingsboard is an open-source IoT platform and device-management application that concentrates vulnerability exposure in a single product serving industrial and enterprise connectivity use cases. The vendor's disclosures skew toward serious outcomes, frequently acquiring public exploit code, and recur through application-layer weakness classes including cross-site scripting, injection flaws, improper privilege management, and access control defects that are characteristic of web-facing platforms handling sensitive device data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thingsboard over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-34282CRITICAL ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG file | Oct 17, 2025 | 9.1 | 47 | NO | YES |
CVE-2022-40004CRITICAL Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log. | Dec 15, 2022 | 9.6 | 30 | NO | NO |
CVE-2022-45608HIGH An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) o | Mar 1, 2023 | 8.8 | 29 | NO | NO |
CVE-2021-42751MEDIUM A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the descri | Aug 12, 2022 | 4.8 | 29 | NO | YES |
CVE-2021-42750MEDIUM A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title | Aug 12, 2022 | 4.8 | 28 | NO | YES |
CVE-2020-27687HIGH ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointi | Dec 18, 2020 | 8.8 | 27 | NO | NO |
CVE-2023-45303HIGH ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execut | Oct 6, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-48341HIGH ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by m | Feb 23, 2023 | 8.8 | 22 | NO | NO |
CVE-2025-34281MEDIUM ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerab | Oct 17, 2025 | 5.4 | 20 | NO | NO |
CVE-2023-26462HIGH ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure forma | Feb 23, 2023 | 8.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thingsboard.
Media articles that mention a CVE ID that affects a product developed by Thingsboard — matched by CVE ID, not by vendor name.