Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Woltlab

First CVE: Oct 4, 2002Active for: 24 yearsTotal CVEs: 46
50.3
VTI Score
TOP TARGET

Woltlab develops a narrow portfolio focused on community and discussion-forum software, primarily its Burning Board product line, which occupies a prominent niche in self-hosted web communities. The vendor's vulnerability profile is characterized by web-application weakness classes—SQL injection, cross-site scripting, cross-site request forgery, and sensitive-information exposure—that reflect the input-handling and session-management demands of forum and user-interaction platforms. While severity tends toward moderate outcomes, the vendor's disclosures frequently acquire public exploit code, making timely patching essential for administrators of exposed forum instances. Defenders should treat Burning Board deployments as requiring priority attention when updates are released, particularly for internet-facing instances; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
46
Total CVEs
More Total CVEs than 98% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Woltlab over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2002
23 years ago
Most Recent CVE
Apr 9, 2010
5,950 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-2569HIGH
SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the c
May 24, 20067.531NOYES
CVE-2010-1338HIGH
SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to execute arbitrary SQL commands via the
Apr 9, 20107.530NOYES
CVE-2007-0812HIGH
SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to execute arbitrary SQL commands via the pmid[0]
Feb 7, 20077.530NOYES
CVE-2006-6237HIGH
SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remote attackers to execute arbitrary SQL commands via the thread
Dec 3, 20067.529NOYES
CVE-2009-2311HIGH
SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to execute arbitrary SQL commands via the userID parameter in the
Jul 2, 20097.528NOYES
CVE-2008-5863HIGH
SQL injection vulnerability in locator.php in the Userlocator module 3.0 for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the y paramet
Jan 6, 20097.528NOYES
CVE-2008-4627HIGH
SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execute arbitrary SQL commands via the itemID parameter in the RG
Oct 21, 20087.528NOYES
CVE-2008-0857HIGH
SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrary SQL commands via the sortOrder parameter to the PMList pag
Feb 21, 20087.528NOYES
CVE-2007-6518HIGH
Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attackers to execute arbitrary SQL commands via the (1) showposts,
Dec 24, 20077.528NOYES
CVE-2007-1518HIGH
SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationids
Mar 20, 20077.528NOYES
View all 46 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products46 CVEs
35%
63%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown46 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown46 (100.0%)
User Interaction
None0 (0.0%)
Unknown46 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown46 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (46 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
29 CVEs
63.0% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Woltlab.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Woltlab — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Woltlab's Products

View all 1 CNAs →

Top CWEs