VendorsUniversity of Californiaboinc_serverall versions
Vulnerabilities

University of California BOINC Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2018-1000875
Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerability in Website Terms of Service Acceptance Page that can result in Access to any user account. This attack appear to be exploitable via Specially crafted URL. This vulnerability appears to have been fixed in 1.0.3.
Published 2018-12-20 · Analyzed
9.8EPSS 0.017
CVE-2025-0668
BOINC Server Multiple SQL Injections
Published 2025-05-07 · Analyzed
9.8EPSS 0.006
CVE-2025-0669
BOINC Server Cross-Site Request Forgery
Published 2025-05-07 · Analyzed
8.8EPSS 0.002
CVE-2025-0667
BOINC Server Stored XSS Injection in pm.php
Published 2025-05-07 · Analyzed
8.7EPSS 0.003
CVE-2025-0666
BOINC Server Stored XSS Injection in host_venue_action.php
Published 2025-05-07 · Analyzed
7.0EPSS 0.003