All 7 CVE vulnerabilities found in ThingsBoard, with AI-generated Chinese analysis, references, and POCs.
Vendor: n/a
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-53676 | ThingsBoard 输入验证错误漏洞 CWE-1321 | - | - | 2026-06-17 |
| CVE-2026-9568 | ThingsBoard YAML provision getGatewayDockerComposeFile code injection CWE-94 | 5.0 | Medium | 2026-05-26 |
| CVE-2025-34282 | ThingsBoard < v4.2.1 SVG Image SSRF CWE-918 | 8.1AI | HighAI | 2025-10-17 |
| CVE-2025-34281 | Stored Cross-Site Scripting (XSS) in ThingsBoard CWE-79 | 5.4AI | MediumAI | 2025-10-17 |
| CVE-2025-9094 | ThingsBoard Add Gateway special elements used in a template engine CWE-1336 | 4.3 | Medium | 2025-08-17 |
| CVE-2024-9358 | ThingsBoard HTTP RPC API resource consumption CWE-400 | 5.3 | Medium | 2024-10-01 |
| CVE-2024-3270 | ThingsBoard AdvancedFeature access control CWE-284 | 3.8 | Low | 2024-04-03 |
All 7 known CVE vulnerabilities affecting ThingsBoard with full Chinese analysis, references, and POCs where available.