The number and severity of CVEs published that impact products developed by V2board over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-37504HIGH Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyController.php, the server authentication token is accepted via GET p | May 1, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-37505MEDIUM SQL Injection via ORDER BY clause in V2Board thru 1.7.4. In app/Http/Controllers/Admin/UserController.php, the sort parameter from user input is passed directly to User::orderBy($s | May 1, 2026 | 4.9 | 22 | NO | NO |
CVE-2026-37503MEDIUM Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade unescaped output in public/theme/v2board/dashboard.blade.php. | May 1, 2026 | 4.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by V2board.
Media articles that mention a CVE ID that affects a product developed by V2board — matched by CVE ID, not by vendor name.