Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-1909
The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insuf…
Buddyboss Platform
2.7.10+
MEDIUM 5.4
CVE-2024-13859
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all version…
Buddyboss Platform
after 2.8.50
MEDIUM 5.4
CVE-2024-13860
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, a…
Buddyboss Platform
after 2.8.50
MEDIUM 5.4
CVE-2024-13858
The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all …
Buddyboss Platform
after 2.8.50
MEDIUM 5.4
CVE-2024-13402
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and in…
Buddyboss Platform
2.8.00+
MEDIUM 5.3
CVE-2024-4750
The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID …
Buddyboss
2.6.0+
MEDIUM 5.4
CVE-2023-32669
Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other…
Buddyboss
Mitigation only
MEDIUM 5.4
CVE-2023-32670
Cross-Site Scripting vulnerability
in BuddyBoss 2.2.9 version
, which could allow a local attacker with basic privileges to execute a malicious pa…
Buddyboss
Mitigation only
MEDIUM 5.4
CVE-2023-32671
A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious j…
Buddyboss
Mitigation only
MEDIUM 5.4
CVE-2021-43334
BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.
Buddyboss
after 1.8.0
MEDIUM 5.3
CVE-2021-44692
BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new user, it generates a Unique ID…
Buddyboss
after 1.8.0
MEDIUM 5.4
CVE-2018-21014
The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.
Buddymoss Media
after 3.2.3