Burning Board

Vendor:

First CVE: Oct 4, 2002 · Active for 23 years

31
Total CVEs
More Total CVEs than 97% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Burning Board over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2002
23 years ago
Most Recent CVE
Sep 9, 2009
6,165 days ago

CVE Severity & Scoring

Burning Board31 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown31 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown31 (100.0%)
User Interaction
None0 (0.0%)
Unknown31 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown31 (100.0%)

Top CVEs

Signals from CVEs in this product scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the c
May 24, 20067.531NOYES
SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrary SQL commands via the sortOrder parameter to the PMList pag
Feb 21, 20087.528NOYES
SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationids
Mar 20, 20077.528NOYES
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQ
Jan 19, 20077.528NOYES
SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.
Jun 28, 20067.528NOYES
SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.
Jun 28, 20067.528NOYES
SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
Jun 28, 20067.528NOYES
SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) inf
Mar 9, 20067.528NOYES
SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) x or (2) y par
Aug 23, 20057.528NOYES
SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.
May 17, 20057.528NOYES

Exploit Exposure

Signals from CVEs in this product scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
18 CVEs
58.1% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (31 CVEs).

Media Mentions

Signals from CVEs in this product scope (31 CVEs).

Top CNAs Publishing CVEs For Burning Board

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0.524.71.4%00
3.0.3_pl117.51.0%01
3.0.116.80.8%01
2.736.41.6%03
2.636.41.6%03
2.536.41.6%03
2.436.41.6%03
2.3.6_pl214.30.5%00
2.3.625.91.1%01
2.3.537.31.2%01
2.3.456.91.2%03
2.3.356.91.4%04
2.3.227.51.1%01
2.3.176.31.5%06
2.3.046.31.3%02
2.2.335.91.4%03
2.2.276.31.5%06
2.2.146.31.3%02
2.1.627.51.1%01
2.1.535.91.4%02