Known Vulnerabilities for UBB.threads by UBB Systems
Listed below are 10 of the newest known vulnerabilities associated with "UBB.threads" by "UBB Systems".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-55205 json | Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/s... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54224 json | UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile on ins... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54223 json | UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file o... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54222 json | UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to intera... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54221 json | UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling atta... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54220 json | uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an atta... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54219 json | UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly sanitize us... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-53673 json | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticat... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-50631 json | A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use se... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-48776 json | LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Pyt... | Not Provided | 2026-06-17 | 2026-06-17 |