CVE Tools

Yabb

19 CVEs tracked since 2000. Since Dec 2000, none of them reached CISA KEV.

Yabb CVEs per month

Dec 2000 to Jun 2007. Point at a month, or focus the strip and use the arrow keys.
Yabb CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2000-1210
2001-0110
2001-02null or fewer
2001-03null or fewer
2001-04null or fewer
2001-05null or fewer
2001-06null or fewer
2001-07null or fewer
2001-08null or fewer
2001-09null or fewer
2001-10null or fewer
2001-11null or fewer
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-03null or fewer
2002-04null or fewer
2002-05null or fewer
2002-06null or fewer
2002-07null or fewer
2002-0810
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-04null or fewer
2003-0510
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-0330
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-0320
2005-04null or fewer
2005-0520
2005-0640
2005-07null or fewer
2005-0820
2005-09null or fewer
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-0620

Products

The products that kept showing up in Yabb's monthly top three, with their CVEs summed over those months.

  1. Yabb1910 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Yabb.

  1. CVE-2013-2057YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability9.8
  2. CVE-2004-2754SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the...7.5
  3. CVE-2002-2296Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbitrary web script or HTML via the num parameter.4.3
  4. CVE-2007-3295Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrary Perl code via a .. (dot dot) in the userlanguage profil...6.5
  5. CVE-2007-3208CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF seque...10.0
  6. CVE-2006-4157Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or HTML via the categories parameter.6.8
  7. CVE-2006-3275SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded user parameter in a viewprofile action.7.5
  8. CVE-2005-4426Interpretation conflict in YaBB before 2.1 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF file extension, which causes the HTML to be execute...4.0
  9. CVE-2003-1277Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information...4.3
  10. CVE-2004-2402Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say th...4.3
  11. CVE-2004-2403Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that spec...10.0
  12. CVE-2005-2296YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.5.0
  13. CVE-2004-2140CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.5.0
  14. CVE-2004-2139Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.7.5
  15. CVE-2002-1845Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) pa...4.3

The record

Peak rank
#30 in Mar 2004
Busiest month shown
Jun 2005, 4 CVEs
Months with a KEV entry
0 since Dec 2000
Monthly snapshots
10 since 2000
Yabb's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store