Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Buddypress MEDIUM 6.1
CVE-2025-23798

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElbowRobo Mass Messaging in BuddyPress mass-mes…

Fix: after 2.2.1
Fix from $1,600 2025-01-22
Buddypress HIGH 8.1
CVE-2024-10011

The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This make…

Fix: after 14.1.0
Fix from $1,950 2024-10-25
Buddypress MEDIUM 5.4
CVE-2024-4892

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 1…

Fix: 12.5.1+
Fix from $1,600 2024-06-12
Buddypress MEDIUM 5.4
CVE-2024-3974

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versions up to, and including, 12.4…

Fix: 12.4.1+
Fix from $1,600 2024-05-14
Buddypress MEDIUM 5.4
CVE-2023-50880

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The BuddyPress Community BuddyPress allows Stor…

Fix: after 11.3.1
Fix from $1,600 2023-12-29
Buddypress HIGH 8.8
CVE-2021-21389EPSS 14%

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-pr…

Fix: 7.2.1+
Fix from $1,950 2021-03-26
Buddypress HIGH 7.5
CVE-2020-5244

In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. Th…

Fix: 5.1.2+
Fix from $1,950 2020-02-24
Buddypress MEDIUM 6.5
CVE-2014-1889EPSS 11%

The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups …

Fix: 1.9.2+
Fix from $1,600 2018-04-10
Buddypress HIGH 7.5
CVE-2012-2109

SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL …

Patch available
Fix from $1,950 2012-09-04