📦 Gnuboard

by Sir

🔍 What is Gnuboard?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-18662

CRITICAL CVSS 9.8 Jun 24, 2021

This CVE describes a SQL injection vulnerability in gnuboard5's installation script that allows attackers to execute arbitrary SQL commands via the table_prefix parameter. It affects gnuboard5 install...

CVE-2022-1252

HIGH CVSS 8.2 Apr 11, 2022

This vulnerability in GnuBoard5 uses weak cryptographic algorithms that allow attackers to decrypt sensitive user information. Attackers can derive email addresses of any user and send emails with con...

CVE-2025-60859

MEDIUM CVSS 6.1 Oct 23, 2025

This is a reflected Cross-Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 that allows authenticated attackers to inject malicious scripts via the c_id parameter in bbs/view_comment.php. The vuln...

CVE-2025-61464

MEDIUM CVSS 6.5 Oct 23, 2025

This vulnerability allows attackers to perform second-order SQL injection attacks in gnuboard4 through the search_table parameter in bbs/search.php. Attackers can inject malicious SQL queries that get...

CVE-2024-37656

MEDIUM CVSS 6.1 Jul 7, 2025

An open redirect vulnerability in gnuboard5 v5.5.16 allows attackers to redirect users to malicious websites by exploiting insufficient URL parameter validation in the logout.php file. This affects al...

CVE-2024-37658

MEDIUM CVSS 6.1 Jul 7, 2025

An open redirect vulnerability in gnuboard5 v5.5.16 allows attackers to redirect users to malicious websites via the bbs/member_confirm.php endpoint. This can lead to phishing attacks, credential thef...

CVE-2024-39097

MEDIUM CVSS 6.1 Aug 26, 2024

This CVE describes an Open Redirect vulnerability in Gnuboard v6.0.4 and earlier versions. Attackers can manipulate the 'url' parameter in the login path to redirect users to malicious websites after ...

CVE-2024-24157

MEDIUM CVSS 6.1 May 14, 2024

This Cross-Site Scripting (XSS) vulnerability in Gnuboard g6 allows attackers to inject malicious scripts into web pages viewed by other users. It affects users of Gnuboard g6 content management syste...