ZeroHour

Vulnerabilities

16 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-12297
A vulnerability was detected in atjiu pybbs up to 6.0.0.

A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.java. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.

NVD description · AI analysis pending
2.1<1% PoC
  • pybbs project pybbs
CVE-2025-8814
+2 in the same advisory: …8813 …8812
A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic.

A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function setCookie of the file src/main/java/co/yiiu/pybbs/util/CookieUtil.java. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 8aa2bb1aef3346e49aec6358edf5e47ce905ae7b. It is recommended to apply a patch to fix this issue.

NVD description · AI analysis pending
2.1
group max
<1% PoC ×2
  • pybbs project pybbs
CVE-2025-8546
A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0.

A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the component Verification Code Handler. The manipulation leads to guessable captcha. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf. It is recommended to apply a patch to fix this issue.

NVD description · AI analysis pending
5.5
group max
<1% PoC ×2
  • pybbs project pybbs
CVE-2022-23391
A cross-site scripting (XSS) vulnerability in Pybbs v6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Searc

A cross-site scripting (XSS) vulnerability in Pybbs v6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Search box.

NVD description · AI analysis pending
6.1<1% PoC
  • pybbs project pybbs
CVE-2020-28702
A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database information.

A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database information.

NVD description · AI analysis pending
7.51% PoC
  • pybbs project pybbs