Thingsboard

Thingsboard

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 27.11.2025 18:15:46
  • Zuletzt bearbeitet 16.12.2025 11:15:44

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • EPSS 0.05%
  • Veröffentlicht 17.10.2025 18:33:41
  • Zuletzt bearbeitet 24.10.2025 13:43:12

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG file that references a remote URL. If the server processes the SVG file in...

  • EPSS 0.04%
  • Veröffentlicht 17.10.2025 18:33:03
  • Zuletzt bearbeitet 10.02.2026 16:16:08

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.08.2025 22:32:05
  • Zuletzt bearbeitet 03.12.2025 13:41:23

A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be initiate...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 12.05.2025 00:00:00
  • Zuletzt bearbeitet 09.07.2025 01:38:44

An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via uploading a crafted file.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 01.10.2024 02:15:10
  • Zuletzt bearbeitet 03.12.2025 14:26:07

A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component HTTP RPC API. The manipulation leads to resource consumption. The attack can be launc...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 03.04.2024 23:15:13
  • Zuletzt bearbeitet 07.02.2025 14:57:36

A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeature. The manipulation leads to improper access controls. The attack can be initiated remotely. The ex...

Exploit
  • EPSS 0.57%
  • Veröffentlicht 06.10.2023 19:15:13
  • Zuletzt bearbeitet 21.11.2024 08:26:43

ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).

  • EPSS 0.09%
  • Veröffentlicht 01.03.2023 16:15:09
  • Zuletzt bearbeitet 07.03.2025 18:15:36

An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN) on the web application. It is important to note that in ...

  • EPSS 0.79%
  • Veröffentlicht 23.02.2023 06:15:10
  • Zuletzt bearbeitet 12.03.2025 15:15:37

ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.