CVE Tools

Deluxebb

29 CVEs tracked since 2005. Since Sep 2005, none of them reached CISA KEV.

Deluxebb CVEs per month

Sep 2005 to Sep 2011. Point at a month, or focus the strip and use the arrow keys.
Deluxebb CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2005-0910
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-0510
2006-0640
2006-0750
2006-0830
2006-0910
2006-1010
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-1210
2008-0110
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-0520
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-0210
2009-0310
2009-04null or fewer
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-10null or fewer
2009-11null or fewer
2009-1240
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-0510
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-09null or fewer
2010-10null or fewer
2010-1110
2010-12null or fewer
2011-01null or fewer
2011-02null or fewer
2011-03null or fewer
2011-04null or fewer
2011-05null or fewer
2011-06null or fewer
2011-07null or fewer
2011-08null or fewer
2011-0910

Products

The products that kept showing up in Deluxebb's monthly top three, with their CVEs summed over those months.

  1. Deluxebb2916 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Deluxebb.

  1. CVE-2011-3725DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by header_html.php.5.0
  2. CVE-2010-4151SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat pa...6.8
  3. CVE-2010-1859SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the membercookie cookie when...6.8
  4. CVE-2009-4467misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail action with the valmem set to a pre-assigned user ID, which is visible from a memb...4.0
  5. CVE-2009-4465DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and configuration information, log data, and gain adminis...7.5
  6. CVE-2009-4466DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in an error message. NOTE: this issue might be re...5.0
  7. CVE-2009-4468Cross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3 allows remote attackers to inject arbitrary web script or HTML via the page parameter.4.3
  8. CVE-2009-1033SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder parameter, a different vector than CVE-2005-2989 and CVE...7.5
  9. CVE-2008-6146SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a delete##### parameter in a Dele...6.8
  10. CVE-2008-2194SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.7.5
  11. CVE-2008-2195Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP code into logs/cp.php via the URI.6.5
  12. CVE-2008-0439Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remote attackers to inject arbitrary web script or HTML via the lang_listofmatche...4.3
  13. CVE-2007-6237cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail...9.0
  14. CVE-2006-5154PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatefolder parameter.7.5
  15. CVE-2006-4558DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileu...7.5

The record

Peak rank
#11 in Jul 2006
Busiest month shown
Jul 2006, 5 CVEs
Months with a KEV entry
0 since Sep 2005
Monthly snapshots
16 since 2005
Deluxebb's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store