Перейти к содержимому
Noroxi

Записи SimpleMachines

31 опубликованных записей вендора simplemachines.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
6
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

31 записей
  • CVE-2011-1127
    41В плане

    SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote a

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    simplemachines · smf20 июн. 2011 г.

  • CVE-2005-4891
    40В плане

    Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary S

    КритическаяCVSS 9,8Proof of conceptEPSS 2 %

    simplemachines · simple machine forum15 янв. 2020 г.

  • CVE-2016-5726
    39Наблюдать

    Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP co

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    simplemachines · simple machines forum9 февр. 2017 г.

  • CVE-2019-11574
    39Наблюдать

    An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    simplemachines · simple machine forum20 мар. 2020 г.

  • CVE-2018-10305
    39Наблюдать

    The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users var

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    simplemachines · simple machines forum23 апр. 2018 г.

  • CVE-2013-7466
    36Наблюдать

    Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traver

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    simplemachines · simple machines forum7 мар. 2019 г.

  • CVE-2016-5727
    35Наблюдать

    LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP co

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    simplemachines · simple machines forum9 февр. 2017 г.

  • CVE-2013-7468
    33Наблюдать

    Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %

    simplemachines · simple machines forum7 мар. 2019 г.

  • CVE-2008-6971
    32Наблюдать

    The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes

    ВысокаяCVSS 7,5Proof of conceptEPSS 7 %

    simplemachines · smf13 авг. 2009 г.

  • CVE-2022-26982
    31Наблюдать

    SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php cod

    ВысокаяCVSS 7,2Proof of conceptEPSS 9 %

    simplemachines · simple machines forum5 апр. 2022 г.

  • CVE-2011-1128
    30Наблюдать

    The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle inv

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    simplemachines · smf20 июн. 2011 г.

  • CVE-2013-7235
    30Наблюдать

    Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space cha

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    simplemachines · simple machines forum29 апр. 2014 г.

  • CVE-2013-7236
    30Наблюдать

    Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph charac

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    simplemachines · simple machines forum29 апр. 2014 г.

  • CVE-2011-3615
    30Наблюдать

    Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    simplemachines · smf24 окт. 2011 г.

  • CVE-2011-1130
    30Наблюдать

    Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    simplemachines · smf20 июн. 2011 г.

  • CVE-2009-5068
    29Наблюдать

    There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3.

    ВысокаяCVSS 7,2Proof of conceptEPSS 2 %

    simplemachines · simple machines forum15 янв. 2020 г.

  • CVE-2011-4173
    27Наблюдать

    Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authen

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    simplemachines · smf24 окт. 2011 г.

  • CVE-2019-12490
    26Наблюдать

    An issue was discovered in Simple Machines Forum (SMF) before 2.0.16.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    simplemachines · simple machines forum22 янв. 2020 г.

  • CVE-2013-4395
    24Наблюдать

    Simple Machines Forum (SMF) through 2.0.5 has XSS

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    simplemachines · simple machines forum12 февр. 2020 г.

  • CVE-2013-7467
    24Наблюдать

    Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    simplemachines · simple machines forum7 мар. 2019 г.

  • CVE-2025-67163
    24Наблюдать

    A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    simplemachines · simple machines forum18 дек. 2025 г.

  • CVE-2024-7438
    21Наблюдать

    SimpleMachines SMF User Alert Read Status index.php resource injection

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    simplemachines · simple machines forum3 авг. 2024 г.

  • CVE-2024-7437
    21Наблюдать

    SimpleMachines SMF Delete User index.php resource injection

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    simplemachines · simple machines forum3 авг. 2024 г.

  • CVE-2013-0192
    20Наблюдать

    File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.

    СредняяCVSS 4,9Proof of conceptEPSS 4 %

    simplemachines · simple machines forum7 февр. 2020 г.

  • CVE-2011-1131
    20Наблюдать

    The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    simplemachines · smf20 июн. 2011 г.