« Volver al listado

Schiocco

Schiocco Support Board: vulnerabilidades y CVE

Schiocco Support Board tiene 10 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses4
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-27395Crítica (9.8)0.48%—17 jun 2026
Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.
CVE-2026-4816Media (4.8)0.23%—25 mar 2026
A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL…
CVE-2026-4815Alta (8.7)0.43%—25 mar 2026
A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve, create, update and delete database via 'calls[0][message_ids][]' parameter in…
CVE-2025-60182Alta (7.1)0.22%—18 dic 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board supportboard allows Reflected XSS.This issue affects Support Board: from n/a through < 3.8.7.
CVE-2025-54031Alta (8.1)0.66%—20 ago 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board supportboard allows PHP Local File Inclusion.This issue affects Support…
CVE-2025-54027Alta (7.1)0.24%—20 ago 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board supportboard allows Reflected XSS.This issue affects Support Board: from n/a through <= 3.8.0.
CVE-2025-4855Crítica (9.8)0.36%—9 jul 2025
The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including,…
CVE-2025-4828Crítica (9.8)0.90%—9 jul 2025
The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete function in all versions up to, and including, 3.8.0. This makes it possible…
CVE-2021-24823Alta (8.1)0.55%—28 feb 2022
The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make…
CVE-2021-24807Media (5.4)1.4%—8 nov 2021
The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to…

Otros productos de Schiocco