Filtered by vendor Bbpress
                         Subscriptions
                    
                    
                
                    Total
                    9 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2025-49959 | 2 Bbpress, Wordpress | 2 Bbpress, Wordpress | 2025-10-23 | 7.1 High | 
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pascal Casier bbPress Move Topics bbp-move-topics allows Reflected XSS.This issue affects bbPress Move Topics: from n/a through <= 1.1.6. | ||||
| CVE-2025-58002 | 2 Bbpress, Wordpress | 2 Bbpress, Wordpress | 2025-09-23 | 6.5 Medium | 
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD bbPress Tools allows DOM-Based XSS. This issue affects GD bbPress Tools: from n/a through 3.5.3. | ||||
| CVE-2025-24763 | 2 Bbpress, Wordpress | 2 Bbpress, Wordpress | 2025-07-12 | 5.3 Medium | 
| Missing Authorization vulnerability in Pascal Casier bbPress API allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress API: from n/a through 1.0.14. | ||||
| CVE-2011-3710 | 1 Bbpress | 1 Bbpress | 2025-04-11 | N/A | 
| bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by bb-templates/kakumei/view.php and certain other files. | ||||
| CVE-2007-3243 | 1 Bbpress | 1 Bbpress | 2025-04-09 | N/A | 
| Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a certain Referer header. | ||||
| CVE-2007-3244 | 1 Bbpress | 1 Bbpress | 2025-04-09 | N/A | 
| SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated by a PRE element, aka the "quircky slashes bug." | ||||
| CVE-2020-13693 | 1 Bbpress | 1 Bbpress | 2024-11-21 | 9.8 Critical | 
| An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled. | ||||
| CVE-2020-13487 | 1 Bbpress | 1 Bbpress | 2024-11-21 | 4.8 Medium | 
| The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI. | ||||
| CVE-2011-1150 | 1 Bbpress | 1 Bbpress | 2024-11-21 | 6.1 Medium | 
| bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter. | ||||
                            
                                
                                
                                    Page 1 of 1.
                                
                                
                            
                        
                     ReportizFlow
ReportizFlow