SIR
SIR Gnuboard: vulnerabilidades y CVE
SIR Gnuboard tiene 39 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE39
Últimos 12 meses2
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-60859 | Media (6.1) | 0.28% | — | 23 oct 2025 | Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via crafted c_id parameter in bbs/view_comment.php. |
| CVE-2025-61464 | Media (6.5) | 0.23% | — | 23 oct 2025 | gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php. |
| CVE-2025-7786 | Baja (2) | 0.25% | — | 18 jul 2025 | A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects some unknown processing of the file /bbs/scrap_popin_update/qa/ of the component Post Reply Handler.… |
| CVE-2024-37658 | Media (6.1) | 0.24% | — | 7 jul 2025 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php. |
| CVE-2024-37657 | Media (6.1) | 0.24% | — | 7 jul 2025 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component. |
| CVE-2024-37656 | Media (6.1) | 0.52% | — | 7 jul 2025 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter verification in bbs/logout.php. |
| CVE-2024-39097 | Media (6.1) | 0.39% | — | 26 ago 2024 | There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path. |
| CVE-2024-41475 | Alta (8.8) | 0.29% | — | 12 ago 2024 | Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration. |
| CVE-2024-24157 | Media (6.1) | 0.41% | — | 14 may 2024 | Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py. |
| CVE-2024-24156 | Media (6.1) | 0.53% | — | 16 mar 2024 | Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execute arbitrary code via the wr_content parameter. |
| CVE-2022-44216 | Alta (7.5) | 0.67% | — | 20 feb 2023 | Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original password. |
| CVE-2022-3963 | Media (5.4) | 0.42% | — | 12 nov 2022 | A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the file bbs/faq.php of the component FAQ Key ID Handler. The manipulation of the argument fm_id leads to… |
| CVE-2022-30050 | Media (6.1) | 0.70% | — | 16 may 2022 | Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php. |
| CVE-2022-1252 | Crítica (9.1) | 0.55% | — | 11 abr 2022 | Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive… |
| CVE-2020-18663 | Media (6.1) | 1.1% | — | 24 jun 2021 | Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php. |
| CVE-2020-18662 | Crítica (9.8) | 5.4% | — | 24 jun 2021 | SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. |
| CVE-2020-18661 | Media (6.1) | 1.1% | — | 24 jun 2021 | Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php. |
| CVE-2018-18674 | Media (6.1) | 1.2% | — | 7 nov 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka the adm/board_form_update.php bo_content_tail parameter. |
| CVE-2018-18678 | Media (6.1) | 1.1% | — | 30 oct 2019 | GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, aka the adm/boardgroup_form_update.php gr_1~10 parameter. |
| CVE-2018-18668 | Media (6.1) | 1.4% | — | 26 ago 2019 | GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka the adm/config_form_update.php cf_title parameter. |
| CVE-2018-18676 | Media (6.1) | 1.6% | — | 23 jul 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter, aka the adm/board_form_update.php bo_mobile_content_tail parameter. |
| CVE-2018-18675 | Media (6.1) | 1.5% | — | 23 jul 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board title contents" parameter, aka the adm/board_form_update.php bo_mobile_subject parameter. |
| CVE-2018-18672 | Media (6.1) | 1.5% | — | 23 jul 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka the adm/board_form_update.php bo_content_head parameter. |
| CVE-2018-18670 | Media (6.1) | 1.5% | — | 23 jul 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the adm/config_form_update.php cf_1~10 parameter. |
| CVE-2018-18673 | Media (6.1) | 1.5% | — | 23 jul 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parameter, aka the adm/menu_list_update.php me_link parameter. |
| CVE-2018-18671 | Media (6.1) | 1.5% | — | 23 jul 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head contents" parameter, aka the adm/board_form_update.php bo_mobile_content_head parameter. |
| CVE-2018-18669 | Media (6.1) | 1.5% | — | 23 jul 2019 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board title contents" parameter, aka the adm/board_form_update.php bo_subject parameter. |
| CVE-2018-15584 | Media (6.1) | 1.1% | — | 26 abr 2019 | Cross-Site Scripting (XSS) vulnerability in adm/boardgroup_form_update.php and adm/boardgroup_list_update.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML. |
| CVE-2018-15582 | Media (6.1) | 1.1% | — | 26 abr 2019 | Cross-Site Scripting (XSS) vulnerability in adm/sms_admin/num_book_write.php and adm/sms_admin/num_book_update.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML. |
| CVE-2018-15581 | Media (6.1) | 1.1% | — | 26 abr 2019 | Cross-Site Scripting (XSS) vulnerability in adm/faqmasterformupdate.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML. |