Releases9
Frequency2 months 1 week
Last Release
Stars6
A simple yet powerful forum software. Download from our website!

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH6.8 MEDIUM

LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.

5.8 MEDIUM

LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.

4.3 MEDIUM

LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).

9.8 CRITICAL7.5 HIGH

LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter.