Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Asgaros Forum HIGH 8.8
CVE-2024-32440

Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.8.0.

Fix: 2.9.0+
Fix from $1,950 2024-04-15
Asgaros Forum CRITICAL 9.8
CVE-2024-22284

Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.7.2.

Fix: 2.8.0+
Fix from $2,300 2024-01-24
Asgaros Forum CRITICAL 9.8
CVE-2023-5604

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configu…

Fix: 2.7.1+
Fix from $2,300 2023-11-27
Asgaros Forum HIGH 8.8
CVE-2022-41608

Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum plugin <= 2.2.0 versions.

Fix: 2.3.0+
Fix from $1,950 2023-05-22
Asgaros Forum HIGH 8.8
CVE-2022-0411

The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST rout…

Fix: 2.0.0+
Fix from $1,950 2022-02-28
Asgaros Forum HIGH 7.2
CVE-2021-25045

The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in a SQL statement when editing …

Fix: 1.15.15+
Fix from $1,950 2022-01-24
Asgaros Forum CRITICAL 9.8
CVE-2021-24827EPSS 13%

The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statem…

Fix: 1.15.13+
Fix from $2,300 2021-11-08