Known Vulnerabilities for products from Minibb

Listed below are 18 of the newest known vulnerabilities associated with the vendor "Minibb".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2018-6506 json Cross-Site Scripting (XSS) exists in the Add Forum feature in the Administrative Panel in miniBB 3.2.2 via crafted use of an ... 4.8 - MEDIUM 2018-02-12 2018-03-06
CVE-2014-9254 json bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduc... Not Provided 2014-12-31 2026-05-06
CVE-2013-5020 json Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before 3.0.1 allow remote attackers to inject a... Not Provided 2013-07-31 2026-04-29
CVE-2008-2067 json SQL injection vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to execute arbitrary SQL commands via the ... Not Provided 2008-05-02 2026-04-23
CVE-2008-2066 json Cross-site scripting (XSS) vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to inject arbitrary web scrip... Not Provided 2008-05-02 2026-04-23
CVE-2008-2029 json Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earlier, w... Not Provided 2008-04-30 2026-04-23
CVE-2008-2028 json miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a dir... Not Provided 2008-04-30 2026-04-23
CVE-2008-2024 json Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, ... Not Provided 2008-04-30 2026-04-23
CVE-2007-5719 json SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL commands via... Not Provided 2007-10-30 2026-04-23
CVE-2007-3272 json Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a .. (dot ... Not Provided 2007-06-19 2026-04-23
CVE-2007-2317 json Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probab... Not Provided 2007-04-26 2026-04-23
CVE-2006-7156 json PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a modul... Not Provided 2007-03-07 2026-04-23
CVE-2006-7153 json PHP remote file inclusion vulnerability in index.php in MiniBB Forum 2 allows remote attackers to execute arbitrary code via ... Not Provided 2007-03-07 2026-04-23
CVE-2006-5674 json Multiple PHP remote file inclusion vulnerabilities in miniBB 2.0.2 and earlier, when register_globals is enabled, allow remot... Not Provided 2006-11-03 2026-04-23
CVE-2006-5673 json PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, all... Not Provided 2006-11-03 2026-04-23
CVE-2006-3955 json Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a allow remote attackers to execute arbitrary PHP code ... 7.5 - HIGH 2006-08-01 2018-10-17
CVE-2006-3690 json Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute arbitra... 7.5 - HIGH 2006-07-21 2018-10-18
CVE-2004-2456 json SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands... Not Provided 2004-12-31 2025-04-03

Known software with vulnerabilities from Minibb

Type Vendor Product Version
ApplicationMinibbMinibb3.1

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report