Total vulnerabilities in the database
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, aka the adm/boardgroup_form_update.php gr_1~10 parameter.
CVSS v3:
CVSS v2:
CWEs:
OWASP TOP 10: