Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ubbcentral

First CVE: Oct 21, 2004Active for: 22 yearsTotal CVEs: 20
43.1
VTI Score
High

Ubbcentral develops UBB.threads, a web-based forum and community platform that has maintained a persistent presence in internet-connected deployments despite its relatively narrow product scope. The vendor's vulnerability profile centers on application-layer input-handling weaknesses endemic to web platforms, including SQL injection, cross-site scripting, cross-site request forgery, and related neutralization flaws that recur across the product's web interface. While the absolute volume of tracked disclosures remains modest, vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the accessibility and appeal of web application flaws to a broad range of threat actors. Defenders should treat UBB.threads instances as requiring timely patching, particularly for publicly disclosed flaws; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ubbcentral over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 21, 2004
21 years ago
Most Recent CVE
Sep 23, 2012
5,052 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-6970HIGH
SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.
Aug 13, 20097.531NOYES
CVE-2006-0545HIGH
SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Num
Feb 4, 20067.531NOYES
CVE-2007-1956HIGH
SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter.
Apr 11, 20077.528NOYES
CVE-2005-2058HIGH
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.ph
Jun 29, 20057.528NOYES
CVE-2004-1622HIGH
SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.
Oct 21, 20047.528NOYES
CVE-2012-5104MEDIUM
Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the Loginname
Sep 23, 20124.325NOYES
CVE-2006-2568MEDIUM
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL
May 24, 20065.125NOYES
CVE-2006-5137MEDIUM
Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] array parameter to admin/doeditthem
Oct 3, 20065.123NOYES
CVE-2006-2675MEDIUM
PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) configd
May 30, 20065.123NOYES
CVE-2004-2510MEDIUM
Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or HTML via the Cat parameter.
Dec 31, 20044.322NOYES
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
65%
35%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (5.0%)
Unknown19 (95.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (5.0%)
High0 (0.0%)
Unknown19 (95.0%)
User Interaction
None0 (0.0%)
Unknown19 (95.0%)
Required1 (5.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (5.0%)
Unknown19 (95.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
60.0% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ubbcentral.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ubbcentral — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ubbcentral's Products

View all 1 CNAs →

Top CWEs