📦 Thingsboard

by Thingsboard

🔍 What is Thingsboard?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-34282

CRITICAL CVSS 9.1 Oct 17, 2025

This SSRF vulnerability in ThingsBoard allows attackers to upload malicious SVG files that trigger outbound requests from the server. Attackers can exploit this to access internal services and resourc...

CVE-2022-45608

HIGH CVSS 8.8 Mar 1, 2023

This vulnerability in ThingsBoard 3.4.1 allows low-privileged CUSTOMER_USER accounts to escalate privileges to TENANT_ADMIN or SYS_ADMIN roles by exploiting an API parameter. Any organization running ...

CVE-2022-48341

HIGH CVSS 8.8 Feb 23, 2023

CVE-2022-48341 is a privilege escalation vulnerability in ThingsBoard where authenticated tenant administrators can modify the scopes parameter to gain system administrator dashboard access. This affe...

CVE-2025-34281

MEDIUM CVSS 5.4 Oct 17, 2025

This CVE describes a stored cross-site scripting (XSS) vulnerability in ThingsBoard's Image Gallery feature. Authenticated users can upload malicious SVG images containing JavaScript, which executes w...

CVE-2024-55466

MEDIUM CVSS 6.5 May 12, 2025

This CVE describes an arbitrary file upload vulnerability in ThingsBoard's Image Gallery component that allows attackers to upload malicious files and execute arbitrary code on affected systems. The v...