thingsboard records
15 published records for vendor thingsboard.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 26.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-269 Improper Privilege Management2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-791 Incomplete Filtering of Special Elements1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2022-40004No exploit | Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Lothingsboard · thingsboard · CWE-79 | Critical9.6 | — | 0.9% | Dec 15, 2022 |
35Monitor | CVE-2020-27687No exploit | ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails.thingsboard · thingsboard · CWE-20 | High8.8 | — | 1.5% | Dec 18, 2020 |
35Monitor | CVE-2022-48341No exploit | ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation.thingsboard · thingsboard · CWE-269 | High8.8 | — | 1.0% | Feb 23, 2023 |
35Monitor | CVE-2022-45608No exploit | An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and thingsboard · thingsboard · CWE-269 | High8.8 | — | 0.9% | Mar 1, 2023 |
35Monitor | CVE-2023-45303No exploit | ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supthingsboard · thingsboard · CWE-74 | High8.8 | — | 0.9% | Oct 6, 2023 |
32Monitor | CVE-2023-26462No exploit | ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escthingsboard · thingsboard · CWE-798 | High8.1 | — | 1.1% | Feb 23, 2023 |
28Monitor | CVE-2025-34282Proof of concept | ThingsBoard < v4.2.1 SVG Image SSRFthingsboard · thingsboard · CWE-918 | Medium6.9 | — | 1.8% | Oct 17, 2025 |
26Monitor | CVE-2024-3270No exploit | ThingsBoard AdvancedFeature access controlthingsboard · thingsboard · CWE-284 | Medium6.5 | — | 0.6% | Apr 3, 2024 |
26Monitor | CVE-2024-55466Proof of concept | An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 thingsboard · thingsboard · CWE-77 | Medium6.5 | — | 0.4% | May 12, 2025 |
24Monitor | CVE-2024-9358No exploit | ThingsBoard HTTP RPC API resource consumptionthingsboard · thingsboard · CWE-400 | Medium6.0 | — | 0.8% | Sep 30, 2024 |
24Monitor | CVE-2025-34281No exploit | Stored Cross-Site Scripting (XSS) in ThingsBoardthingsboard · thingsboard · CWE-79 | Medium6.2 | — | 0.4% | Oct 17, 2025 |
21Monitor | CVE-2022-31861No exploit | Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.thingsboard · thingsboard · CWE-79 | Medium5.4 | — | 0.6% | Sep 13, 2022 |
20Monitor | CVE-2021-42750Proof of concept | A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injecthingsboard · thingsboard · CWE-79 | Medium4.8 | — | 3.1% | Aug 12, 2022 |
20Monitor | CVE-2021-42751Proof of concept | A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injecthingsboard · thingsboard · CWE-79 | Medium4.8 | — | 3.1% | Aug 12, 2022 |
8Monitor | CVE-2025-9094No exploit | ThingsBoard Add Gateway special elements used in a template enginethingsboard · thingsboard · CWE-791 | Low2.1 | — | 0.3% | Aug 17, 2025 |
- CVE-2022-4000438Monitor
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Lo
CriticalCVSS 9.6No exploitEPSS 1%thingsboard · thingsboardDec 15, 2022
- CVE-2020-2768735Monitor
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails.
HighCVSS 8.8No exploitEPSS 2%thingsboard · thingsboardDec 18, 2020
- CVE-2022-4834135Monitor
ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation.
HighCVSS 8.8No exploitEPSS 1%thingsboard · thingsboardFeb 23, 2023
- CVE-2022-4560835Monitor
An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and
HighCVSS 8.8No exploitEPSS 1%thingsboard · thingsboardMar 1, 2023
- CVE-2023-4530335Monitor
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker sup
HighCVSS 8.8No exploitEPSS 1%thingsboard · thingsboardOct 6, 2023
- CVE-2023-2646232Monitor
ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege esc
HighCVSS 8.1No exploitEPSS 1%thingsboard · thingsboardFeb 23, 2023
- CVE-2025-3428228Monitor
ThingsBoard < v4.2.1 SVG Image SSRF
MediumCVSS 6.9Proof of conceptEPSS 2%thingsboard · thingsboardOct 17, 2025
- CVE-2024-327026Monitor
ThingsBoard AdvancedFeature access control
MediumCVSS 6.5No exploitEPSS 1%thingsboard · thingsboardApr 3, 2024
- CVE-2024-5546626Monitor
An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1
MediumCVSS 6.5Proof of conceptEPSS 0%thingsboard · thingsboardMay 12, 2025
- CVE-2024-935824Monitor
ThingsBoard HTTP RPC API resource consumption
MediumCVSS 6.0No exploitEPSS 1%thingsboard · thingsboardSep 30, 2024
- CVE-2025-3428124Monitor
Stored Cross-Site Scripting (XSS) in ThingsBoard
MediumCVSS 6.2No exploitEPSS 0%thingsboard · thingsboardOct 17, 2025
- CVE-2022-3186121Monitor
Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.
MediumCVSS 5.4No exploitEPSS 1%thingsboard · thingsboardSep 13, 2022
- CVE-2021-4275020Monitor
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injec
MediumCVSS 4.8Proof of conceptEPSS 3%thingsboard · thingsboardAug 12, 2022
- CVE-2021-4275120Monitor
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injec
MediumCVSS 4.8Proof of conceptEPSS 3%thingsboard · thingsboardAug 12, 2022
- CVE-2025-90948Monitor
ThingsBoard Add Gateway special elements used in a template engine
LowCVSS 2.1No exploitEPSS 0%thingsboard · thingsboardAug 17, 2025