Zeroboard is a web-based bulletin-board and content-management platform whose vulnerability footprint concentrates in application-layer input-handling defects, including cross-site scripting, SQL injection, and code-injection issues characteristic of web application security. The vendor's disclosures frequently acquire public exploit code, underscoring the accessibility of these weakness classes to a broad range of attackers. Defenders deploying Zeroboard should prioritize input validation and sanitization hardening; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zeroboard over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1820HIGH zboard.php in Zeroboard version 4.1pl2 to 4.1pl5 allows remote attackers to execute arbitrary PHP code via improper quoting when using the preg_replace function. | Jun 1, 2005 | 7.5 | 29 | NO | YES |
CVE-2012-4743HIGH Multiple SQL injection vulnerabilities in ssearch.php in Siche search module 0.5 for Zeroboard allow remote attackers to execute arbitrary SQL commands via the (1) ss, (2) sm, (3) | Aug 31, 2012 | 7.5 | 23 | NO | NO |
CVE-2004-1419MEDIUM PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.ph | Dec 31, 2004 | 6.8 | 23 | NO | NO |
CVE-2002-1704MEDIUM Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP code by modifying the _zb_path parameter to | Dec 31, 2002 | 5.0 | 23 | NO | YES |
CVE-2005-0380HIGH Multiple PHP remote file inclusion vulnerabilities in (1) print_category.php, (2) login.php, (3) setup.php, (4) ask_password.php, or (5) error.php in ZeroBoard 4.1pl5 and earlier a | May 2, 2005 | 7.5 | 21 | NO | NO |
CVE-2012-4744MEDIUM Cross-site scripting (XSS) vulnerability in ssearch.php in the Siche search module 0.5 for Zeroboard allows remote attackers to inject arbitrary web script or HTML via the search p | Aug 31, 2012 | 4.3 | 17 | NO | NO |
CVE-2006-3070MEDIUM write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with mod_mime, allows remote attackers to bypass restrictions for uploading files with executable extensions by uploadin | Jun 19, 2006 | 5.0 | 15 | NO | NO |
CVE-2005-0379MEDIUM Multiple directory traversal vulnerabilities in ZeroBoard 4.1pl5 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the _zb_path parameter to (1) _hea | May 2, 2005 | 5.0 | 15 | NO | NO |
CVE-2006-1222MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in zeroboard 4.1 pl7 allows allow remote attackers to inject arbitrary web script or HTML via the (1) memo box title, (2) user e | Mar 14, 2006 | 4.3 | 14 | NO | NO |
CVE-2005-0495MEDIUM Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php | Feb 19, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zeroboard.
Media articles that mention a CVE ID that affects a product developed by Zeroboard — matched by CVE ID, not by vendor name.