Xennobb maintains a narrowly scoped product line centered on its eponymous offering, which despite minimal disclosure volume occupies a more prominent position in tracked vulnerability assessments than its size might suggest. The observed vulnerability surface reflects general or unclassified weakness patterns, limiting the precision of structural analysis at this volume; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xennobb over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4279HIGH SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the icon_topic parameter. | Aug 21, 2006 | 7.5 | 34 | NO | YES |
CVE-2006-4025HIGH SQL injection vulnerability in profile.php in XennoBB 2.1.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) bday_day, (2) bday_month, an | Aug 9, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-4161MEDIUM Directory traversal vulnerability in the avatar_gallery action in profile.php in XennoBB 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the | Aug 16, 2006 | 5.0 | 23 | NO | YES |
Cross-site scripting (XSS) vulnerability in messages.php in XennoBB 1.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the tid parameter. | Jun 27, 2006 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xennobb.
Media articles that mention a CVE ID that affects a product developed by Xennobb — matched by CVE ID, not by vendor name.