Extension WordPress
Vulnérabilités Support Board
Cette page rassemble les failles publiées pour Support Board, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Support Board
12 fiches
Support Board < 3.8.9 – Unauthenticated Privilege Escalation
The Support Board plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 3.8.9 (exclusive). This makes it possible for unauthenticated attackers to elevate their privileges.
[*, 3.8.9)
3.8.9
01/06/2026
Support Board < 3.8.7 – Reflected Cross-Site Scripting
The Support Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 3.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
[*, 3.8.7)
3.8.7
31/07/2025
Support Board <= 3.8.0 – Reflected Cross-Site Scripting
The Support Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-3.8.0
3.8.1
23/07/2025
Support Board <= 3.8.0 – Unauthenticated Local File Inclusion
The Support Board plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution…
*-3.8.0
3.8.1
22/07/2025
Support Board <= 3.8.0 – Unauthenticated Arbitrary File Deletion
The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete function in all versions up to, and including, 3.8.0. This makes it possible for attackers to delete…
*-3.8.0
3.8.1
08/07/2025
Support Board <= 3.8.0 – Unauthenticated Authorization Bypass due to Use of Default Secret Key
The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated…
*-3.8.0
3.8.1
08/07/2025
Support Board <= 3.4.1 – Authenticated SQL Injection
The Support Board plugin for WordPress is vulnerable to generic SQL Injection via several parameters in versions up to, and including, 3.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
[*, 3.4.2)
3.4.2
19/01/2022
Support Board < 3.3.6 – Cross-Site Request Forgery
The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete…
[*, 3.3.6)
3.3.6
18/10/2021
Support Board <= 3.3.4 – Agent+ Stored Cross-Site Scripting
The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will…
*-3.3.4
3.3.5
07/10/2021
Support Board <= 3.3.3 – Multiple Unauthenticated SQL Injections
The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.
*-3.3.3
3.3.4
03/09/2021
Support Board <= 1.2.8 – Authenticated Stored Cross-Site Scripting
The Support Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts…
[*, 1.2.9)
1.2.9
11/06/2019
Support Board for WordPress <= 1.2.3 – Cross-Site Scripting
In the Schiocco "Support Board – Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been discovered in file upload areas in the Chat and Help Desk sections via the msg parameter in a…
[*, 1.2.4)
1.2.4
16/10/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.