VYPR
Vendor

Apboard

Products
2
CVEs
6
Across products
6
Status
Private

Products

2

Recent CVEs

6
  • CVE-2025-59835HigOct 2, 2025
    risk 0.49cvss —epss 0.00

    LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attackers can exploit the /api/v1/files/documents interface to perform arbitrary file uploads. Since this interface does not strictly restrict the storage directory…

  • CVE-2026-90562HigSep 13, 2026
    risk 0.46cvss 8.1epss 0.00

    LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the…

  • CVE-2005-3746Nov 22, 2005
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in thread.php in APBoard allows remote attackers to execute arbitrary SQL commands via the start parameter.

  • CVE-2026-28509MedMar 6, 2026
    risk 0.00cvss 6.3epss 0.00

    LangBot is a global IM bot platform designed for LLMs. Prior to version 4.8.7, LangBot’s web UI renders user-supplied raw HTML using rehypeRaw, which can lead to a cross-site scripting (XSS) vulnerability. This issue has been patched in version 4.8.7.

  • CVE-2006-3078Jun 19, 2006
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in APBoard 2.2-r3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) PHPSESSID parameter in board.php and (2) viewcatmod parameter in main.php.

  • CVE-2002-2398Dec 31, 2002
    risk 0.00cvss —epss 0.01

    The new thread posting page in APBoard 2.02 and 2.03 allows remote attackers to post messages to protected forums by modifying the insertinto parameter.