Yabb
19 CVEs tracked since 2000. Since Dec 2000, none of them reached CISA KEV.
Yabb CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2000-12 | 1 | 0 |
| 2001-01 | 1 | 0 |
| 2001-02 | null or fewer | |
| 2001-03 | null or fewer | |
| 2001-04 | null or fewer | |
| 2001-05 | null or fewer | |
| 2001-06 | null or fewer | |
| 2001-07 | null or fewer | |
| 2001-08 | null or fewer | |
| 2001-09 | null or fewer | |
| 2001-10 | null or fewer | |
| 2001-11 | null or fewer | |
| 2001-12 | null or fewer | |
| 2002-01 | null or fewer | |
| 2002-02 | null or fewer | |
| 2002-03 | null or fewer | |
| 2002-04 | null or fewer | |
| 2002-05 | null or fewer | |
| 2002-06 | null or fewer | |
| 2002-07 | null or fewer | |
| 2002-08 | 1 | 0 |
| 2002-09 | null or fewer | |
| 2002-10 | null or fewer | |
| 2002-11 | null or fewer | |
| 2002-12 | null or fewer | |
| 2003-01 | null or fewer | |
| 2003-02 | null or fewer | |
| 2003-03 | null or fewer | |
| 2003-04 | null or fewer | |
| 2003-05 | 1 | 0 |
| 2003-06 | null or fewer | |
| 2003-07 | null or fewer | |
| 2003-08 | null or fewer | |
| 2003-09 | null or fewer | |
| 2003-10 | null or fewer | |
| 2003-11 | null or fewer | |
| 2003-12 | null or fewer | |
| 2004-01 | null or fewer | |
| 2004-02 | null or fewer | |
| 2004-03 | 3 | 0 |
| 2004-04 | null or fewer | |
| 2004-05 | null or fewer | |
| 2004-06 | null or fewer | |
| 2004-07 | null or fewer | |
| 2004-08 | null or fewer | |
| 2004-09 | null or fewer | |
| 2004-10 | null or fewer | |
| 2004-11 | null or fewer | |
| 2004-12 | null or fewer | |
| 2005-01 | null or fewer | |
| 2005-02 | null or fewer | |
| 2005-03 | 2 | 0 |
| 2005-04 | null or fewer | |
| 2005-05 | 2 | 0 |
| 2005-06 | 4 | 0 |
| 2005-07 | null or fewer | |
| 2005-08 | 2 | 0 |
| 2005-09 | null or fewer | |
| 2005-10 | null or fewer | |
| 2005-11 | null or fewer | |
| 2005-12 | null or fewer | |
| 2006-01 | null or fewer | |
| 2006-02 | null or fewer | |
| 2006-03 | null or fewer | |
| 2006-04 | null or fewer | |
| 2006-05 | null or fewer | |
| 2006-06 | null or fewer | |
| 2006-07 | null or fewer | |
| 2006-08 | null or fewer | |
| 2006-09 | null or fewer | |
| 2006-10 | null or fewer | |
| 2006-11 | null or fewer | |
| 2006-12 | null or fewer | |
| 2007-01 | null or fewer | |
| 2007-02 | null or fewer | |
| 2007-03 | null or fewer | |
| 2007-04 | null or fewer | |
| 2007-05 | null or fewer | |
| 2007-06 | 2 | 0 |
Products
The products that kept showing up in Yabb's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Yabb.
- CVE-2013-2057YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability9.8
- CVE-2004-2754SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the...7.5
- CVE-2002-2296Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbitrary web script or HTML via the num parameter.4.3
- CVE-2007-3295Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrary Perl code via a .. (dot dot) in the userlanguage profil...6.5
- CVE-2007-3208CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF seque...10.0
- CVE-2006-4157Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or HTML via the categories parameter.6.8
- CVE-2006-3275SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded user parameter in a viewprofile action.7.5
- CVE-2005-4426Interpretation conflict in YaBB before 2.1 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF file extension, which causes the HTML to be execute...4.0
- CVE-2003-1277Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information...4.3
- CVE-2004-2402Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say th...4.3
- CVE-2004-2403Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that spec...10.0
- CVE-2005-2296YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.5.0
- CVE-2004-2140CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.5.0
- CVE-2004-2139Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.7.5
- CVE-2002-1845Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) pa...4.3
The record
- Peak rank
- #30 in Mar 2004
- Busiest month shown
- Jun 2005, 4 CVEs
- Months with a KEV entry
- 0 since Dec 2000
- Monthly snapshots
- 10 since 2000