Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Buddyforms MEDIUM 5.3
CVE-2025-62973

Missing Authorization vulnerability in Themekraft BuddyForms buddyforms allows Accessing Functionality Not Properly Constrained by ACLs.This issue af…

Fix: after 2.9.0
Fix from $1,600 2025-10-27
Buddyforms HIGH 8.8
CVE-2025-32151

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themekraft BuddyForms buddyf…

Fix: after 2.8.15
Fix from $1,950 2025-04-04
Buddyforms MEDIUM 5.4
CVE-2024-12038

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner…

Fix: 2.8.16+
Fix from $1,600 2025-02-22
Buddyforms MEDIUM 5.4
CVE-2024-47377

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themekraft BuddyForms buddyforms allows Stored …

Fix: 2.8.13+
Fix from $1,600 2024-10-05
Buddyforms HIGH 8.8
CVE-2024-8246

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner…

Fix: 2.8.12+
Fix from $1,950 2024-09-14
Buddypress Woocommerce My Account Integration. Create Woocommerce Member Pages HIGH 8.8
CVE-2024-35726

Missing Authorization vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.19.

Fix: 3.4.20+
Fix from $1,950 2024-06-10
Buddyforms MEDIUM 5.3
CVE-2024-5149

The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insuffic…

Fix: after 2.8.9
Fix from $1,600 2024-06-05
Buddyforms HIGH 7.5
CVE-2024-32830

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forg…

Fix: 2.8.9+
Fix from $1,950 2024-05-17
Buddypress Woocommerce My Account Integration HIGH 8.8
CVE-2024-32603

Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20.

Fix: 3.4.21+
Fix from $1,950 2024-04-18
Buddyforms MEDIUM 6.1
CVE-2024-30198

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeKraft BuddyForms allows Reflected XSS.This…

Fix: 2.8.6+
Fix from $1,600 2024-03-27
Post Form HIGH 8.2
CVE-2024-1170

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner…

Fix: 2.8.8+
Fix from $1,950 2024-03-07
Post Form HIGH 7.5
CVE-2024-1169

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner…

Fix: 2.8.8+
Fix from $1,950 2024-03-07
Tk Google Fonts Gdpr Compliant HIGH 8.8
CVE-2023-5823

Cross-Site Request Forgery (CSRF) vulnerability in ThemeKraft TK Google Fonts GDPR Compliant plugin <= 2.2.11 versions.

Fix: after 2.2.11
Fix from $1,950 2023-11-06
Post Form MEDIUM 5.4
CVE-2023-25981

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form plugin <= 2.8.1 versions.

Fix: after 2.8.1
Fix from $1,600 2023-08-25
Post Form Registration Form Profile Form For User Profiles And Content Forms MEDIUM 5.4
CVE-2022-38971

Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for Us…

Fix: after 2.7.5
Fix from $1,600 2023-03-16
Buddyforms CRITICAL 9.8
CVE-2023-26326

The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated at…

Fix: 2.7.8+
Fix from $2,300 2023-02-23
Buddyforms CRITICAL 9.8
CVE-2018-21003

The buddyforms plugin before 2.2.8 for WordPress has SQL injection.

Fix: 2.2.8+
Fix from $2,300 2019-08-27