Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2025-62973 Missing Authorization vulnerability in Themekraft BuddyForms buddyforms allows Accessing Functionality Not Properly Constrained by ACLs.This issue af… Buddyforms after 2.9.0 Fix from $1,6002025-10-27 HIGH 8.8 CVE-2025-32151 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themekraft BuddyForms buddyf… Buddyforms after 2.8.15 Fix from $1,9502025-04-04 MEDIUM 5.4 CVE-2024-12038 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner… Buddyforms 2.8.16+ Fix from $1,6002025-02-22 MEDIUM 5.4 CVE-2024-47377 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themekraft BuddyForms buddyforms allows Stored … Buddyforms 2.8.13+ Fix from $1,6002024-10-05 HIGH 8.8 CVE-2024-8246 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner… Buddyforms 2.8.12+ Fix from $1,9502024-09-14 HIGH 8.8 CVE-2024-35726 Missing Authorization vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.19. Buddypress Woocommerce My Account Integration. Create Woocommerce Member Pages 3.4.20+ Fix from $1,9502024-06-10 MEDIUM 5.3 CVE-2024-5149 The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insuffic… Buddyforms after 2.8.9 Fix from $1,6002024-06-05 HIGH 7.5 CVE-2024-32830 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forg… Buddyforms 2.8.9+ Fix from $1,9502024-05-17 HIGH 8.8 CVE-2024-32603 Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20. Buddypress Woocommerce My Account Integration 3.4.21+ Fix from $1,9502024-04-18 MEDIUM 6.1 CVE-2024-30198 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeKraft BuddyForms allows Reflected XSS.This… Buddyforms 2.8.6+ Fix from $1,6002024-03-27 HIGH 8.2 CVE-2024-1170 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner… Post Form 2.8.8+ Fix from $1,9502024-03-07 HIGH 7.5 CVE-2024-1169 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner… Post Form 2.8.8+ Fix from $1,9502024-03-07 HIGH 8.8 CVE-2023-5823 Cross-Site Request Forgery (CSRF) vulnerability in ThemeKraft TK Google Fonts GDPR Compliant plugin <= 2.2.11 versions. Tk Google Fonts Gdpr Compliant after 2.2.11 Fix from $1,9502023-11-06 MEDIUM 5.4 CVE-2023-25981 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form plugin <= 2.8.1 versions. Post Form after 2.8.1 Fix from $1,6002023-08-25 MEDIUM 5.4 CVE-2022-38971 Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for Us… Post Form Registration Form Profile Form For User Profiles And Content Forms after 2.7.5 Fix from $1,6002023-03-16 CRITICAL 9.8 CVE-2023-26326 The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated at… Buddyforms 2.7.8+ Fix from $2,3002023-02-23 CRITICAL 9.8 CVE-2018-21003 The buddyforms plugin before 2.2.8 for WordPress has SQL injection. Buddyforms 2.2.8+ Fix from $2,3002019-08-27