Thingsboard
15 known vulnerabilities
Top Products
ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Galle
A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Ha
An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard
A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability
A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because A
An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileg
ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usab
ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Adminis
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted
Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrat
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrat
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send
Frequently Asked Questions
How many CVEs affect Thingsboard?
Thingsboard has 15 CVE records in our database, including 2 critical and 5 high severity vulnerabilities.
What are the most severe Thingsboard vulnerabilities?
Thingsboard has 2 critical severity (CVSS 9.0+) and 5 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Thingsboard vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Thingsboard products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Thingsboard Vulnerabilities
CyberStrike scans your infrastructure for Thingsboard vulnerabilities and provides real-time remediation guidance.
Get Started