Schiocco
Schiocco Support Board: vulnerabilidades y CVE
Schiocco Support Board tiene 10 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses4
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-27395 | Crítica (9.8) | 0.48% | — | 17 jun 2026 | Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. |
| CVE-2026-4816 | Media (4.8) | 0.23% | — | 25 mar 2026 | A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL… |
| CVE-2026-4815 | Alta (8.7) | 0.43% | — | 25 mar 2026 | A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve, create, update and delete database via 'calls[0][message_ids][]' parameter in… |
| CVE-2025-60182 | Alta (7.1) | 0.22% | — | 18 dic 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board supportboard allows Reflected XSS.This issue affects Support Board: from n/a through < 3.8.7. |
| CVE-2025-54031 | Alta (8.1) | 0.66% | — | 20 ago 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board supportboard allows PHP Local File Inclusion.This issue affects Support… |
| CVE-2025-54027 | Alta (7.1) | 0.24% | — | 20 ago 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board supportboard allows Reflected XSS.This issue affects Support Board: from n/a through <= 3.8.0. |
| CVE-2025-4855 | Crítica (9.8) | 0.36% | — | 9 jul 2025 | The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including,… |
| CVE-2025-4828 | Crítica (9.8) | 0.90% | — | 9 jul 2025 | The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete function in all versions up to, and including, 3.8.0. This makes it possible… |
| CVE-2021-24823 | Alta (8.1) | 0.55% | — | 28 feb 2022 | The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make… |
| CVE-2021-24807 | Media (5.4) | 1.4% | — | 8 nov 2021 | The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to… |