Usebb is a modestly represented forum and community platform software that, despite a narrow product focus, occupies a prominent position in the vulnerability landscape due to its widespread deployment across hosted and self-hosted discussion communities. Its vulnerability profile centers on the single Usebb product and recurs through application-layer weakness classes including cross-site request forgery, improper input validation, and related web-tier flaws that are typical of community-facing software, with a meaningful share of disclosures reaching serious severity and a tendency toward public exploit availability. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Usebb over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3963HIGH Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_IN | Jul 25, 2007 | 9.3 | 33 | NO | YES |
CVE-2020-8088CRITICAL panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandles hashes that begin with 0e followed by | Jan 27, 2020 | 9.8 | 29 | NO | NO |
CVE-2011-3612HIGH Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12. | Jan 22, 2020 | 8.8 | 28 | NO | NO |
CVE-2011-3611HIGH A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12. | Jan 22, 2020 | 7.2 | 24 | NO | NO |
CVE-2005-2439HIGH SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function. | Aug 3, 2005 | 7.5 | 19 | NO | NO |
CVE-2006-2524MEDIUM Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors when processing the use | May 22, 2006 | 6.8 | 18 | NO | NO |
CVE-2010-3713MEDIUM rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permission, which allows remote attackers to b | Oct 28, 2010 | 4.3 | 17 | NO | NO |
CVE-2006-2525MEDIUM SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list search module. | May 22, 2006 | 6.4 | 17 | NO | NO |
CVE-2009-4041MEDIUM UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags. | Nov 20, 2009 | 5.0 | 15 | NO | NO |
CVE-2007-2066MEDIUM UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspecified script, which reveals the path in | Apr 18, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Usebb.
Media articles that mention a CVE ID that affects a product developed by Usebb — matched by CVE ID, not by vendor name.