Woltlab develops a narrow portfolio focused on community and discussion-forum software, primarily its Burning Board product line, which occupies a prominent niche in self-hosted web communities. The vendor's vulnerability profile is characterized by web-application weakness classes—SQL injection, cross-site scripting, cross-site request forgery, and sensitive-information exposure—that reflect the input-handling and session-management demands of forum and user-interaction platforms. While severity tends toward moderate outcomes, the vendor's disclosures frequently acquire public exploit code, making timely patching essential for administrators of exposed forum instances. Defenders should treat Burning Board deployments as requiring priority attention when updates are released, particularly for internet-facing instances; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Woltlab over time
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2569HIGH SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the c | May 24, 2006 | 7.5 | 31 | NO | YES |
CVE-2010-1338HIGH SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to execute arbitrary SQL commands via the | Apr 9, 2010 | 7.5 | 30 | NO | YES |
CVE-2007-0812HIGH SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to execute arbitrary SQL commands via the pmid[0] | Feb 7, 2007 | 7.5 | 30 | NO | YES |
CVE-2006-6237HIGH SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remote attackers to execute arbitrary SQL commands via the thread | Dec 3, 2006 | 7.5 | 29 | NO | YES |
CVE-2009-2311HIGH SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to execute arbitrary SQL commands via the userID parameter in the | Jul 2, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-5863HIGH SQL injection vulnerability in locator.php in the Userlocator module 3.0 for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the y paramet | Jan 6, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-4627HIGH SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execute arbitrary SQL commands via the itemID parameter in the RG | Oct 21, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-0857HIGH SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrary SQL commands via the sortOrder parameter to the PMList pag | Feb 21, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-6518HIGH Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attackers to execute arbitrary SQL commands via the (1) showposts, | Dec 24, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-1518HIGH SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationids | Mar 20, 2007 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Woltlab.
Media articles that mention a CVE ID that affects a product developed by Woltlab — matched by CVE ID, not by vendor name.