Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Buddyboss Platform CRITICAL 9.8
CVE-2025-1909

The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insuf…

Fix: 2.7.10+
Fix from $2,300 2025-05-05
Buddyboss Platform MEDIUM 5.4
CVE-2024-13859

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all version…

Fix: after 2.8.50
Fix from $1,600 2025-05-02
Buddyboss Platform MEDIUM 5.4
CVE-2024-13860

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, a…

Fix: after 2.8.50
Fix from $1,600 2025-05-02
Buddyboss Platform MEDIUM 5.4
CVE-2024-13858

The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all …

Fix: after 2.8.50
Fix from $1,600 2025-05-02
Buddyboss Platform MEDIUM 5.4
CVE-2024-13402

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and in…

Fix: 2.8.00+
Fix from $1,600 2025-02-27
Buddyboss MEDIUM 5.3
CVE-2024-4750

The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID …

Fix: 2.6.0+
Fix from $1,600 2024-06-04
Buddyboss MEDIUM 5.4
CVE-2023-32669

Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other…

Mitigation only
Fix from $1,600 2023-10-03
Buddyboss MEDIUM 5.4
CVE-2023-32670

Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious pa…

Mitigation only
Fix from $1,600 2023-10-03
Buddyboss MEDIUM 5.4
CVE-2023-32671

A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious j…

Mitigation only
Fix from $1,600 2023-10-03
Buddyboss MEDIUM 5.4
CVE-2021-43334

BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.

Fix: after 1.8.0
Fix from $1,600 2022-01-26
Buddyboss MEDIUM 5.3
CVE-2021-44692

BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new user, it generates a Unique ID…

Fix: after 1.8.0
Fix from $1,600 2022-01-26
Buddymoss Media MEDIUM 5.4
CVE-2018-21014

The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.

Fix: after 3.2.3
Fix from $1,600 2019-09-09