Yabb is a web forum software platform with a focused product line centered on the Yabb and Yabb SE community applications. Despite its narrow scope, the vendor ranks among the more prominent fixtures in the vulnerability landscape, and its disclosures have a strong tendency toward public exploit availability, reflecting the appeal of forum software as a target for remote code execution and data extraction attacks. The recurring vulnerability patterns cluster around application-layer input handling: cross-site scripting, SQL injection, and unrestricted file uploads recur across versions and point to the parser and database-interaction demands of a user-generated-content platform. Defenders operating Yabb forum instances should treat input-validation advisories as high-priority and maintain vigilant update cycles; current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yabb over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0955HIGH Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitrary script as other web site vi | Oct 4, 2002 | 7.5 | 38 | NO | YES |
CVE-2004-0343HIGH Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the pos | Nov 23, 2004 | 10.0 | 35 | NO | YES |
CVE-2002-0117HIGH Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary script and steal cookies via a message | Mar 25, 2002 | 7.5 | 35 | NO | YES |
CVE-2013-2057CRITICAL YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability | Feb 11, 2020 | 9.8 | 30 | NO | NO |
CVE-2000-1176HIGH Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field. | Jan 9, 2001 | 7.5 | 30 | NO | YES |
CVE-2004-2754HIGH SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER | Dec 31, 2004 | 7.5 | 28 | NO | YES |
CVE-2004-0291MEDIUM SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter. | Nov 23, 2004 | 5.0 | 28 | NO | YES |
CVE-2007-3208HIGH CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that | Jun 14, 2007 | 10.0 | 27 | NO | NO |
CVE-2006-4157MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or HTML via the categories paramet | Aug 16, 2006 | 6.8 | 27 | NO | YES |
CVE-2000-0853MEDIUM YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Nov 14, 2000 | 5.0 | 27 | NO | YES |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yabb.
Media articles that mention a CVE ID that affects a product developed by Yabb — matched by CVE ID, not by vendor name.