Myupb
Myupb Ultimate PHP Board: vulnerabilities and CVEs
Myupb Ultimate PHP Board has 4 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months2
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61540 | Medium (6.5) | 0.29% | — | Oct 16, 2025 | SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php. |
| CVE-2025-61539 | Medium (6.1) | 0.27% | — | Oct 16, 2025 | Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php. |
| CVE-2015-2217 | Medium (4.3) | 1.9% | — | Mar 10, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Ultimate PHP Board (aka myUPB) before 2.2.8 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to search.php or (2) avatar… |
| CVE-2003-0395 | High (7.5) | 2.5% | — | Jul 2, 2003 | Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the… |