Thwboard is a narrowly scoped collaboration or project-management platform with a focused vulnerability footprint concentrated in its core product and beta releases. Despite the modest volume, the vendor's disclosures have a notable tendency to acquire public exploit code, making patching relevant to users who operate internet-accessible instances. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thwboard over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0340HIGH SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execute arbitrary SQL commands via the board[styleid] parameter t | Jan 18, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-4139HIGH Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user | Dec 9, 2005 | 7.5 | 28 | NO | YES |
CVE-2006-1926MEDIUM SQL injection vulnerability in showtopic.php in ThWboard 2.84 beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the pagenum parameter. | Apr 20, 2006 | 5.0 | 22 | NO | YES |
CVE-2006-2037MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0 Beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the navpath parameter. | Apr 26, 2006 | 4.3 | 21 | NO | YES |
CVE-2003-1185HIGH Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Ann | Nov 3, 2003 | 7.5 | 19 | NO | NO |
CVE-2005-4138MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) Wohnort and (2) Beruf f | Dec 9, 2005 | 4.3 | 14 | NO | NO |
CVE-2004-1779MEDIUM Cross-site scripting (XSS) vulnerability in board.php for ThWboard before beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the lastvisited parameter. | Dec 31, 2004 | 4.3 | 14 | NO | NO |
CVE-2003-1184MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the p | Nov 3, 2003 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thwboard.
Media articles that mention a CVE ID that affects a product developed by Thwboard — matched by CVE ID, not by vendor name.