Skip to content
Noroxi

thingsboard records

15 published records for vendor thingsboard.

All records

15 records
  • Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Lo

    CriticalCVSS 9.6No exploitEPSS 1%

    thingsboard · thingsboardDec 15, 2022

  • ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails.

    HighCVSS 8.8No exploitEPSS 2%

    thingsboard · thingsboardDec 18, 2020

  • ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation.

    HighCVSS 8.8No exploitEPSS 1%

    thingsboard · thingsboardFeb 23, 2023

  • An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and

    HighCVSS 8.8No exploitEPSS 1%

    thingsboard · thingsboardMar 1, 2023

  • ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker sup

    HighCVSS 8.8No exploitEPSS 1%

    thingsboard · thingsboardOct 6, 2023

  • ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege esc

    HighCVSS 8.1No exploitEPSS 1%

    thingsboard · thingsboardFeb 23, 2023

  • ThingsBoard < v4.2.1 SVG Image SSRF

    MediumCVSS 6.9Proof of conceptEPSS 2%

    thingsboard · thingsboardOct 17, 2025

  • CVE-2024-3270
    26Monitor

    ThingsBoard AdvancedFeature access control

    MediumCVSS 6.5No exploitEPSS 1%

    thingsboard · thingsboardApr 3, 2024

  • An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1

    MediumCVSS 6.5Proof of conceptEPSS 0%

    thingsboard · thingsboardMay 12, 2025

  • CVE-2024-9358
    24Monitor

    ThingsBoard HTTP RPC API resource consumption

    MediumCVSS 6.0No exploitEPSS 1%

    thingsboard · thingsboardSep 30, 2024

  • Stored Cross-Site Scripting (XSS) in ThingsBoard

    MediumCVSS 6.2No exploitEPSS 0%

    thingsboard · thingsboardOct 17, 2025

  • Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.

    MediumCVSS 5.4No exploitEPSS 1%

    thingsboard · thingsboardSep 13, 2022

  • A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injec

    MediumCVSS 4.8Proof of conceptEPSS 3%

    thingsboard · thingsboardAug 12, 2022

  • A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injec

    MediumCVSS 4.8Proof of conceptEPSS 3%

    thingsboard · thingsboardAug 12, 2022

  • ThingsBoard Add Gateway special elements used in a template engine

    LowCVSS 2.1No exploitEPSS 0%

    thingsboard · thingsboardAug 17, 2025