Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2025-62973
Missing Authorization vulnerability in Themekraft BuddyForms buddyforms allows Accessing Functionality Not Properly Constrained by ACLs.This issue af…
Buddyforms
after 2.9.0
HIGH 8.8
CVE-2025-32151
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themekraft BuddyForms buddyf…
Buddyforms
after 2.8.15
MEDIUM 5.4
CVE-2024-12038
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner…
Buddyforms
2.8.16+
MEDIUM 5.4
CVE-2024-47377
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themekraft BuddyForms buddyforms allows Stored …
Buddyforms
2.8.13+
HIGH 8.8
CVE-2024-8246
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner…
Buddyforms
2.8.12+
HIGH 8.8
CVE-2024-35726
Missing Authorization vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.19.
Buddypress Woocommerce My Account Integration. Create Woocommerce Member Pages
3.4.20+
MEDIUM 5.3
CVE-2024-5149
The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insuffic…
Buddyforms
after 2.8.9
HIGH 7.5
CVE-2024-32830
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forg…
Buddyforms
2.8.9+
HIGH 8.8
CVE-2024-32603
Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20.
Buddypress Woocommerce My Account Integration
3.4.21+
MEDIUM 6.1
CVE-2024-30198
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeKraft BuddyForms allows Reflected XSS.This…
Buddyforms
2.8.6+
HIGH 8.2
CVE-2024-1170
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner…
Post Form
2.8.8+
HIGH 7.5
CVE-2024-1169
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner…
Post Form
2.8.8+
HIGH 8.8
CVE-2023-5823
Cross-Site Request Forgery (CSRF) vulnerability in ThemeKraft TK Google Fonts GDPR Compliant plugin <= 2.2.11 versions.
Tk Google Fonts Gdpr Compliant
after 2.2.11
MEDIUM 5.4
CVE-2023-25981
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form plugin <= 2.8.1 versions.
Post Form
after 2.8.1
MEDIUM 5.4
CVE-2022-38971
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for Us…
Post Form Registration Form Profile Form For User Profiles And Content Forms
after 2.7.5
CRITICAL 9.8
CVE-2023-26326
The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated at…
Buddyforms
2.7.8+
CRITICAL 9.8
CVE-2018-21003
The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
Buddyforms
2.2.8+