Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Simple Machines Forum MEDIUM 6.1
CVE-2025-67163

A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injec…

Mitigation only
Fix from $1,600 2025-12-18
Simple Machines Forum MEDIUM 6.1
CVE-2025-2583

A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown part of the file ManageNews.php…

No fix yet
Fix from $1,600 2025-03-21
Simple Machines Forum MEDIUM 5.4
CVE-2025-2582

A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file…

No fix yet
Fix from $1,600 2025-03-21
Simple Machines Forum HIGH 7.2
CVE-2022-26982EPSS 9%

SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because…

Fix: after 2.1.1
Fix from $1,950 2022-04-05
Simple Machine Forum CRITICAL 9.8
CVE-2019-11574

An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-sup…

Fix: 2.0.17+
Fix from $2,300 2020-03-20
Simple Machines Forum MEDIUM 6.1
CVE-2013-4395

Simple Machines Forum (SMF) through 2.0.5 has XSS

Fix: after 2.0.5
Fix from $1,600 2020-02-12
Simple Machines Forum MEDIUM 6.5
CVE-2019-12490

An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _blank for external links.

Fix: 2.0.16+
Fix from $1,600 2020-01-22
Simple Machines Forum HIGH 7.2
CVE-2009-5068

There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is…

Fix: after 2.0.3
Fix from $1,950 2020-01-15
Simple Machine Forum CRITICAL 9.8
CVE-2005-4891

Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statem…

Fix: after 1.0.4
Fix from $2,300 2020-01-15
Simple Machines Forum HIGH 8.8
CVE-2013-7466

Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in th…

No fix yet
Fix from $1,950 2019-03-07
Simple Machines Forum HIGH 8.1
CVE-2013-7468

Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.

No fix yet
Fix from $1,950 2019-03-07
Simple Machines Forum MEDIUM 6.1
CVE-2013-7467

Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.

No fix yet
Fix from $1,600 2019-03-07
Simple Machines Forum CRITICAL 9.8
CVE-2018-10305

The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in …

Fix: 2.0.15+
Fix from $2,300 2018-04-24
Simple Machines Forum CRITICAL 9.8
CVE-2016-5726

Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via th…

Patch available
Fix from $2,300 2017-02-09
Simple Machines Forum HIGH 8.8
CVE-2016-5727

LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via ve…

Patch available
Fix from $1,950 2017-02-09
Simple Machines Forum HIGH 7.5
CVE-2013-7235

Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space characters c…

Fix: after 1.1.9
Fix from $1,950 2014-04-29
Simple Machines Forum HIGH 7.5
CVE-2013-7236

Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a …

Fix: after 1.1.9
Fix from $1,950 2014-04-29
Smf MEDIUM 6.8
CVE-2011-4173

Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authentication …

Mitigation only
Fix from $1,600 2011-10-24
Smf HIGH 7.5
CVE-2011-3615

Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute arbitrary …

Fix: after 1.1.14
Fix from $1,950 2011-10-24
Smf HIGH 10.0
CVE-2011-1127

SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote attackers …

Fix: after 1.1.12
Fix from $1,950 2011-06-21
Smf HIGH 7.5
CVE-2011-1128

The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle invalid logi…

Fix: after 1.1.12
Fix from $1,950 2011-06-21
Smf HIGH 7.5
CVE-2011-1130

Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote attackers…

Fix: after 1.1.12
Fix from $1,950 2011-06-21
Smf MEDIUM 5.0
CVE-2011-1131

The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a situation…

Fix: after 1.1.12
Fix from $1,600 2011-06-21
Smf HIGH 7.5
CVE-2008-6971EPSS 7%

The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues abo…

Patch available
Fix from $1,950 2009-08-13
Smf MEDIUM 5.1
CVE-2006-4564

SQL injection vulnerability in Sources/ManageBoards.php in Simple Machines Forum 1.1 RC3 allows remote attackers to execute arbitrary SQL commands vi…

Mitigation only
Fix from $1,600 2006-09-06