Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Thingsboard

15 known vulnerabilities

2
CRITICAL
5
HIGH
7
MEDIUM
1
LOW

Top Products

thingsboard 15
15 CVEs
9.1
CVE-2025-34282

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload

5.4
CVE-2025-34281

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Galle

4.3
CVE-2025-9094

A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Ha

6.5
CVE-2024-55466

An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard

5.3
CVE-2024-9358

A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability

3.8
CVE-2024-3270

A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code

8.4
CVE-2023-45303

ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because A

8.8
CVE-2022-45608

An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileg

8.1
CVE-2023-26462

ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usab

8.8
CVE-2022-48341

ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Adminis

9.6
CVE-2022-40004

Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted

5.4
CVE-2022-31861

Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.

4.8
CVE-2021-42751

A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrat

4.8
CVE-2021-42750

A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrat

8.8
CVE-2020-27687

ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send

Frequently Asked Questions

How many CVEs affect Thingsboard?

Thingsboard has 15 CVE records in our database, including 2 critical and 5 high severity vulnerabilities.

What are the most severe Thingsboard vulnerabilities?

Thingsboard has 2 critical severity (CVSS 9.0+) and 5 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Thingsboard vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Thingsboard products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Thingsboard Vulnerabilities

CyberStrike scans your infrastructure for Thingsboard vulnerabilities and provides real-time remediation guidance.

Get Started