Skip to main content

Vendor archive

myupb CVEs

Beta · best-effort

7 CVEs tagged to vendor myupb0 Critical, 2 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2025-61539

Published Oct 16, 2025

Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2217

Published Mar 10, 2015

Multiple cross-site scripting (XSS) vulnerabilities in Ultimate PHP Board (aka myUPB) before 2.2.8 allow remote attackers to inject arbitrary web script or HTML via the (1) q para…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6727

Published Apr 20, 2009

Cross-site scripting (XSS) vulnerability in Ultimate PHP Board (UPB) 2.2.2, 2.2.1, and earlier 2.x versions allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6396

Published Dec 17, 2007

Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inject arbitrary PHP code via the (1) username, (2) password,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6399

Published Dec 17, 2007

index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HT…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0395

Published Jul 2, 2003

Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent head…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1